Visa Gift Card Hack

Visa Gift Card Hack

  1. Gift Card Hacking Programs
  2. Vanilla Gift Card Balance
  3. Visa Gift Card Hacked

I’m pretty sure I’m not the only one who wasn’t always a fan of getting gift cards as a gift growing up. To me, gift cards just weren’t sentimental. They were an uncomplicated escape for someone who felt the need to give a gift. While I was happy to be receiving anything at all, I’m someone who believes that presents should have a personal touch and have meaning. Gift cards absolved the buyer of all obligation and meant that whatever I purchased only meant something to me. No memories shared.

As time went on, I found gift cards to be a permanent thing in my life, so I resolved to accept them. Even in the freelance world, companies were offering to make payment via gift cards instead of sending payments to our bank account. Admittedly being paid via Sephora gift cards wasn’t that bad as I always had a new beauty product that I wanted to purchase (you can read how I stay on budget and still look great here), but when I companies started sending Visa/Mastercard/Amex gift cards myself and many other fellow freelancers weren’t to hip to the idea.

4 comments on “ Gift card hack exposed – you pay, they play ” Steve C# says: November 24, 2020 at 7:03 pm. I really like the suggestions at the end of the article. Paul Ducklin says. Using your Visa Gift card in stores and online. In a store, you’ll just slide or insert your Visa card to pay. For an online checkout, you’ll enter your Visa gift card’s 16-digit number, expiration date and CVV in the appropriate form field. Like the gift card hack above, you’ll want to buy an egift card for the same dollar amount remaining on the Visa gift card. For example, if you have a Visa gift card with $27.99 on it and you want to use that card to buy a $40 sweater at JCPenney, then first buy a JCPenney egift card for $27.99.

Here’s why cash based gift cards don’t work for most people.

  1. They’re too restrictive: Have you ever taken a look at the terms and conditions that come along with a gift card? Yes, it’s technically you’re money; however, here’s a limited list of things you can do with it.
  2. They expire: The thought of money expiring still blows my mind, yet if you don’t use your gift card promptly you may lose all the money on it or a small portion of it every year after a specific date (it’s all in those pesky terms and conditions)
  3. You can’t get cash back. The money has to stay on the gift card. Meaning you have to keep up with exactly how much you spent at all times and only use the card for that amount or it can be declined.
  4. Some gift cards don’t allow you to use them to make online purchases. While there are some gift cards out there that let you register your name and address so that you can use them online, there are many that don’t. You can only use them in brick and mortar stores. There go those pesky restrictions again.

After receiving over $1000 in payments via Visa gift cards from a company, I was fed up and decided to try something that in theory seemed like a logical solution however the means by which I was hoping to achieve this had never been tested.

I was going to send myself an invoice and use the gift cards to pay myself with this Ultimate Gift Card Hack!

Sounds easy enough, right?

Here’s how to do it!

To set things into motion, I created an alternate PayPal email address.

I then added the visa gift cards as payment cards onto that PayPal account

Next, I proceeded to try and send money to myself as a friend.

Now here is where it gets a bit tricky because like me Paypal wants to be paid if we use their service so I had to make sure I calculated how much I would be assessed in fee’s when sending the payment (use this nifty calculator here). For instance, if I only had a card that had $100 on it, I could only pay myself $96.80. This way, the remaining balance would cover the fee.

Okay, so you might be thinking, “but, you’re losing money this way!”

Yes, you are, but think about it, would you instead pocket $96.80 in cash or be held captive by a piece of plastic for $3.20?

Visa

“I’ll take the cash for $100 Bob!”

So let’s carry on. Once you’ve paid the invoice you’ll get an alert via email, text, facebook, however, you’ve got it set up that you have sent yourself money and bippity boppity boop the money is now in your personal account and no longer on a gift card!

Now if a company insist on paying me via gift card, I don’t bother to argue because I know I can get the money off quickly and easily. If you need a video walk-thru on how to, this is done, I shared it on my IG storiesunder “Money Hacks.”

Give it a try and let me know how it works for you. I promise you’ll never look monetary gift cards (AMEX/Visa/MasterCard) the same way again.

Gift cards have caused quite a headache for retailers in the last month, exposing another way that fraudulent activity can eat into razor-thin profit margins. Gift card fraud can range from physical theft to cloning to exploiting programming errors on the merchant side.

The methods of attack are very similar to what is seen with credit card fraud, but gift card fraud is less widely reported in the news. The reason is that, unlike data breaches that involve credit cards, personally identifiable information (PII) is rarely disclosed. Regardless, it is important for both merchants and customers to know how gift card fraud occurs, so they can recognize the behavior and protect themselves.

On June 1st, Australian retailer Woolworth’s experienced a data breach that led to AUS $1.3 million worth of gift card numbers being leaked online. Several weeks prior, Starbucks had two high-profile gift card incidents – one involved a security researcher that discovered a race condition that allowed him to transfer card balances between cards without deducting any value, and the other involved the auto-load feature on cards that allowed fraudsters to quickly drain attached bank accounts. According to reporting by Brian Krebs, Starbucks itself was not hacked – the customers were.

The article goes on to explain that customers often use the same username/password combination across multiple sites and when a website is hacked, cyber criminals will often take the password dumps and try them on multiple sites. This is what most likely happened to the Starbucks customers; it’s very inconvenient and costly to the victim but avoidable, if good password habits are used.

There are many ways to commit fraud using gift cards and they are very alluring, for many reasons. First, and foremost, there’s a low chance of being prosecuted. The dollar amounts on each individual transaction are relatively small and not enough to garner the attention of large law enforcement agencies that have the ability to catch the perpetrators. Second, it’s very easy to commit fraud. Lastly, it’s easy to convert gift card value into money or merchandise.

How is gift card fraud commonly committed? There are three primary categories of fraud:

Hacking accounts

Gift Card Hacking Programs

As described earlier with the Starbucks story, thieves can hack into gift card accounts and quickly drain them of money. If the auto-load feature is turned on, within seconds, a cybercriminal can quickly rack up charges and start the process of moving money off the compromised gift card account.

Another common route is using gift cards to quickly monetize the value in other hacked accounts, such as credit card rewards programs or hotel points.

This is how it works:

Hack walmart gift card torrent
  • A cybercriminal will obtain the username and password to a person’s credit card rewards program, usually through reused credentials or malware.
  • They will log in and check the value of the account. For example, let’s say it’s $5,000.
  • Credit card redemption programs offer many different items they can redeem in exchange for points. Several problems exist for the fraudster. They can’t exactly redeem for golf clubs – where would they ship them? Cash back is either redeemed as statement credit or sent as a check to the cardholder – also no good. Gift cards, however, are a perfect way to quickly monetize the hack.
  • The redeemer instantly gets an e-gift card number that can be spent immediately, meaning the fraudster can exchange $5,000 worth of points for $5,000 worth of value on an e-gift card. The site will give the fraudster a gift card number on the spot, which can be printed out and used in-store or online.
  • The fraudster will then use a service that converts gift cards into cash, such as cardcash.com or cardhub.com. One can usually get 60% of the face value of typical gift cards on sites like this. There are also physical kiosks in malls that offer the same service.
  • The fraudster can now effectively convert a point or rewards on a hacked account into real cash.

Stealing numbers and cloning cards

Another very common method of gift card fraud is committed is through stealing numbers off physical gift cards. Gift cards work essentially the same as credit cards with a mag stripe—the gift card number is printed on the card for manual key entry and is also encoded on a mag stripe on the back of the card.

The mag stripe number is plain text and can be read with a mag stripe reader purchased for $15 from eBay or an electronics store. Gift cards may or may not have an additional level of security, a PIN number covered with a coating, similar to a lottery ticket, that needs to be scratched off.

Some merchants, such as Starbucks, do not require the customer to enter in a PIN number when using the card. The customer simply swipes the card and they’re good to go. Other merchants do use PIN numbers, which offers an additional layer of protection – the redeemer needs to have the physical card in possession in order to use it.

Gift cards are not usable until they are activated at the cash register. In many stores, gift cards are sitting out in an accessible place. People have been known to steal a stack of cards, bring them home, write down the numbers (or script it out using a mag stripe reader) and then sneak them back into the store and place them on the shelf.

Brazen criminals can write down or take pictures of the numbers down right in the store. From there, it’s a waiting game. Most merchants offer a way to check gift card balances online – the fraudsters will repeatedly check balances on the merchant’s website and wait until they are activated by a legitimate purchase. When they are, transferring balances to another card or converting into cash by using a third-party redeemer drains the balances out.

There are no reported incidents of POS skimmers used to grab gift card numbers, but this attack would work as well.

The addition of a PIN number can delay a fraudster, but not deter them entirely. They can scratch off the coating, revealing the PIN and replace it with a new sticker easily purchased from eBay.

Visa

This type of fraud is fairly low-level and does not result in a huge loss to the merchant, but is quite a shock to the customer when the recipient of a gift card tries to redeem it and finds that the balance is zero. Some retailers will reimburse the customer with the face value of the gift card, but this ends up being a reputational hit for the retailer, as well as a headache for the consumer.

Acquiring numbers in bulk

Visa Gift Card Hack

Slightly more difficult, but much more rewarding, is to acquire gift card numbers in bulk from the issuers, merchant, reward redemption program, etc. This can be done through a multitude of methods, including phishing, SQL injection, social engineering and accidental disclosure.

Accidental disclosure is exactly what happened at Woolworth’s, where an employee at the company had a spreadsheet with 8,000 gift card numbers, totaling AUS $1.3 million. The employee accidentally sent the email to more than 1,000 people. Anyone who received the email could immediately go shopping or start to convert the gift card numbers into cash.

Advice for retailers

In-store security is important. Store gift cards behind the counter or locked in a cabinet. It’s not advisable to leave them out in an area that is publicly accessible because of the high probability someone will perpetrate one of the scams described above.

It’s even more important to have good policies and procedures in place for the central handling of gift cards numbers. First, require a PIN for the use of a gift card. Next, on a corporate policy level, never store the gift card PINs with the gift card numbers – keep the two separate. Last, limit online balance look-ups to several per hour, maximum.

Advice for customers

The best advice for customers buying gift cards is to only buy gift cards from reputable merchants. Always look at the physical card and look for signs of tampering, such as a scratched off and/or replaced PIN number. Most importantly – keep your receipt. If you get the card home and find it drained of funds, you may be able to recoup your losses by going to the merchant that sold the card or the store where the gift card is redeemable.

Gift card fraud is pretty unsexy when compared with the latest nation-state threat actors exploiting multiple 0-day vulnerabilities, but it is a significant problem that drains money from retailers and consumers alike. By being aware of how this fraud is committed, we can spot the scams and protect ourselves.

See how solutions like Tripwire equipped the Walgreens-Boots Alliance to continuously monitor and protect the business, while ensuring systems are reliable and secure.

About the Author:Tony Martin-Vegue is a 20-year Information Security veteran with expertise in network operations, cryptography and risk management. He’s worked for large global organizations, leading cyber-crime programs, enterprise risk management and security programs. He is a blogger and host of The Standard Deviant Security Podcast, a podcast that, with candor and cleverness, holds up a mirror to industry truths.Tony holds a Bachelor of Science in Business Economics from the University of San Francisco and has many certifications such as CISSP, CISM and CEH. He can be found on the web at www.thestandarddeviant.com and on Twitter @tdmv.

Vanilla Gift Card Balance

Editor’s Note:The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

Visa Gift Card Hacked

Title image courtesy of ShutterStock