The stand-alone ATM, similar to the one pictured, was positioned outside the security office and contained a PC set to skim card details and PINs.
Scammers at the Riviera Hotel Casino clearly failed to check the event calendar when the installed a fake cashpoint - and were duly shut down by eagle-eyed hackers attending the DefCon convention.
As reported over on
Wired, the ATM - which was placed in the hotel's conference centre where the DefCon convention was taking place - appeared to be a standard stand-alone unit, sat outside of the range of surveillance cameras. Sadly for anyone that needed a quick buck or two to feed into the slot machines, the device hid a card skimmer - designed to record the account details and PIN of any card inserted.
It isn't known how long the machine was in place, nor who installed it - but it is known that hacker and CEO of Aries Security Brian Markus is responsible for getting it removed. Having spotted that the smoked glass on the front of the unit - which usually hides a small camera positioned to record the face of anyone using the machine for fraud prevention purposes - looked "
funny", he shone a torch at the machine to peek behind the panel. Rather than the expected camera, Markus saw a PC connected to the machine's innards - and recording card information.
Although the ATM was carefully positioned to avoid hotel security cameras, whoever put the device in place clearly had a sense of irony as it was placed directly outside the hotel's security office - with none of the security employees any the wiser that something was amiss until Markus pointed out his suspicions.
The ATM has since been removed by hotel security staff, and an investigation is taking place to discover exactly how long the skimmer was in place - and hopefully find those responsible.
Do you think that the crooks behind this scheme had the worst timing - trying to scam a hacker convention - or could it have been placed by one of the conference attendees in order to teach his fellow hackers a lesson in information security? Share your thoughts over in
the forums.
Or a case of over confidence so they could brag after the convention that so many so-called "security experts" got hoodwinked into using a tampered with ATM.
I suspect the former, no one would be stupid enough to try the latter unless they were insanely good.
Kudos to whomever did that!
Yours in Romulan Pin Plasma,
Star*Dagger
They probably set it up so they never had to return to it
Maybe the guy had it placed there so he could then 'discover' it and get the kudos from all at the convention for being so awesome?
Hope the security staff are embarassed... :D
http://i121.photobucket.com/albums/o227/CFranklin_2007/FUNNY%20SHIT/63b6.jpg
smart but i hope they get caught still, i hate credit card scammers
I think this is one of the hackers having fun, or trying to prove point of security situational awareness.
So seeing someone get cash before you do is no safety.
Haven't heard of complete false machines though...
oh no doubt, on the casino floor your on camera up to 1200 times, off the casino floor your on camera around 700 times, and walking down the strip your on camera at least 500 times (I use to work in Vegas) so ya they will certainly have something on camera and most casinos have griffin teams in place working with facial recognition software so it shouldnt take to long. Its always amusing to see someone try to rip off a casino, you would have better luck robbing a bank and getting away with it then ripping off a casino in Vegas lol