Hacker News new | ask | show | jobs
by mathattack 4693 days ago
What makes you say it was from a database leak?

I had a fraud issue caught by a bank once. What's strange is they caught the test at a bar I had frequented. That made me assume that it was skimmed. (But perhaps they saw many others tested there?)

1 comments

It's unlikely for a skimmed card to be used online in this fashion, because the thieves wouldn't typically have the CVV2, only the CVV1 which is included on the magnetic stripe track. Most merchants which offer gift card reloads will decline on an incorrect CVV2.

Additionally, cost benefit wise, card data sells for $2-3 max, while track data sells for much much more ($25-50), and typically someone capable of acquiring this data themselves would not be wasting their time with Starbucks card reloads.

Interesting. Thanks!