Bangalore Correspondent

BBC says UK credit card information for sale in India

news
Mar 20, 20093 mins

Nearly all the names, addresses, and post codes sold to BBC team were valid, but most of the numbers attached to them were invalid -- often out by a single digit

Reporters from the BBC posing as fraudsters claim they bought names, addresses, and valid credit card details of U.K. residents from a man the BBC identified as Saurabh Sachar in Delhi.

Two BBC undercover reporters met the broker in a Delhi coffee shop for an encounter that was filmed secretly, according to a report on the BBC Web site that was also broadcast.

[ Roger Grimes details a few real-life tales of corporate espionage in “Countering the computer spies” | Learn how to secure your systems with Roger Grimes’ Security Adviser blog and newsletter, both from InfoWorld. ]

Sachar told the reporters that he could supply them with hundreds of credit and debit card details each week at a cost of $10 a card. He said some of the numbers had been obtained from call centers handling mobile phone sales or payments for phone bills, the BBC said.

After the reporters agreed to initially buy the details of 50 cards, the man handed over a list of 14. He said the remainder would be sent later by e-mail. Back in the United Kingdom, the broker continued to supply card details to one of the undercover reporters by e-mail, the BBC said.

Nearly all of the names, addresses, and post codes sold to the BBC team were valid, the BBC said. But most of the numbers attached to them were invalid — often out by a single digit, it added.

Three of the persons whose details were provided to the undercover reporters had bought software from Symantec by giving their credit card details to a call center over the phone.

APACS, the U.K. trade association for the payments industry, said in a report released on Thursday that card fraud losses totaled £609.9 million ($874 million) last year. There are two main areas of fraud. First, criminals use the numbers of stolen credit cards in transactions not protected by chip and PIN (personal identification number), specifically via the Internet, phone, and regular mail. The second type involves the physical use of stolen credit cards abroad by criminals in countries yet to upgrade to chip and PIN.

The outsourcing of work to Indian call centers and BPO (business process outsourcing) companies has been often criticized in the United Kingdom. Besides cutting into jobs in the United Kingdom, outsourcing to India could compromise the U.K.’s tough data protection laws, critics have said.

The Amicus trade union in the United Kingdom, now merged into Unite trade union, warned in 2004 that offshoring is “an accident waiting to happen.”

Indian call centers claim that they have introduced technology and restrictions to prevent data theft. Offices are under electronic surveillance, and employees are not allowed to carry in paper or mobile phones, and they can’t access the Internet while at work.

There have been some complaints lodged with the Indian police in the past about data thefts at call centers, but the Indian call center industry holds that the incidents are far fewer than in other countries including the United Kingdom and the United States.