How the $45 million ATM heist worked: prepaid cards with no limits
About $40 million came out of ATMs in 24 countries in roughly 10 hours in February 2013, and the thieves never touched a bank vault or a customer's account.[1] The money came from a handful of prepaid cards whose limits had been erased inside a card processor's systems. This case file covers how the scheme worked, how the New York cashing crew was caught, what it cost, and the one control that was missing.
What happened
Prosecutors in Brooklyn called these "unlimited operations." A hacking team would break into a company that processes prepaid debit cards for a bank, steal card data, and lift the withdrawal limits and balances on those cards. The card numbers and PINs went out to crews in many countries, who copied them onto blank magnetic-stripe cards and waited for a start signal.[1][3]
The first big run in this series hit in February 2011 and took about $10 million through some 15,000 withdrawals in 18 countries.[3] On December 21 and 22, 2012, the crew hit prepaid travel cards issued by the National Bank of Ras Al-Khaimah in the United Arab Emirates, whose cards were processed by a company in India. That run took about $5 million from roughly 4,500 withdrawals in about 20 countries, including nearly $400,000 from more than 140 ATMs in New York City in under 2.5 hours.[1][5]
Then came the big one. On February 19, 2013, the cashers went to work on prepaid cards issued by Bank Muscat of Oman, handled by a different card processor with offices in India.[1][5] Over about 10 hours they made roughly 36,000 withdrawals in 24 countries and took about $40 million. In New York alone, the local cell made about 2,904 withdrawals and collected $2.4 million between 3 p.m. on February 19 and 1:26 a.m. the next morning.[1]
How it worked
A prepaid debit card normally carries a fixed balance and a daily withdrawal cap. Those numbers live not on the card but in the systems of the processor that authorizes each transaction. According to prosecutors, the hackers got into those processor networks, gave themselves administrator-level privileges, and changed the settings on a small number of cards so that both the balance and the cap disappeared.[1][4] Bank Muscat said only about a dozen prepaid travel cards were involved in its losses.[6]
That is the trick at the heart of the scheme. The same few card numbers could be cloned onto many plastic cards and used at thousands of machines at once, and every request was approved because the system saw no limit to hit. The attack only stopped when someone at the issuer or processor noticed and shut the cards down.[1] Nothing checked whether a single prepaid card making thousands of withdrawals across 2 dozen countries in one night made any sense.
How it was caught
Cash on that scale is hard to hide. Prosecutors said the New York cell laundered its take through bank deposits, including nearly $150,000 in $20 bills paid into a single branch in Miami, and spent it on luxury goods. The government seized cash, 2 Rolex watches and a Mercedes SUV, and moved to forfeit a Porsche.[1][2] On May 9, 2013, federal prosecutors in Brooklyn charged 8 members of the New York cell with access device fraud and money laundering conspiracy.[1] Their alleged leader had been killed in the Dominican Republic in April 2013, before the charges were announced.[1] By November 12, 2013, 3 members, Evan Jose Peña, Elvis Rafael Rodriguez and Emir Yasser Yeje, had pleaded guilty.[2]
The hacker at the top took longer. Ercan Findikoglu, a Turkish national prosecutors described as a leader of all 3 operations, was brought to the U.S., pleaded guilty on March 1, 2016, and on February 10, 2017, was sentenced to 8 years in prison and ordered to pay more than $55 million in restitution.[3][4]
What it cost
The 3 operations together took more than $55 million.[3] Bank Muscat put its own loss at about $39 million, roughly a tenth of its expected earnings for the year, and later said its insurers had agreed to cover it.[6][7] The processors' names ended up in headlines around the world, and the Indian processor that handled Bank Muscat's cards said its customers had been harmed by what it called a sophisticated crime.[5]
The missing control
The missing control: vendor controls on prepaid card limits. The banks let an outside processor hold the switch that set how much money each card could release, with no independent check on changes to it and no hard ceiling the vendor could not override.
If raising a card's limit had required approval from someone outside the processor's own admin accounts, or if the bank had set a firm cap that no processor setting could lift, the stolen access would have been worth far less. A simple velocity rule, flagging a single card used hundreds of times in an hour, would have stopped the run early instead of after 10 hours.[1] The banks outsourced the work. They could not outsource the risk.
What to do in your business
- Know which vendors can move your money. List every payroll service, payment processor, card program and bookkeeping app that can change payment amounts or limits on your behalf.
- Set hard limits in your own accounts. Use your bank's controls for daily transfer, card and ACH limits, so a vendor or intruder cannot push past them.
- Require a second approval for limit changes. Ask your bank and vendors to require dual approval, and a notice to you, whenever a limit, payee or payout setting changes.
- Turn on real-time alerts. Get text or email alerts for large withdrawals, many small ones in a row, and activity from other countries.
- Ask vendors how they protect admin access. Ask whether admin logins use multi-factor login and how quickly they will tell you about a breach. Put the answers in the contract.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the Caesars hack happened: a con at the outsourced IT help desk
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Attorney's Office, E.D.N.Y.: Eight members of New York cell of cybercrime organization indicted in $45 million cybercrime campaign
- U.S. Attorney's Office, E.D.N.Y.: Members of New York cell of cybercrime organization plead guilty in $45 million cybercrime campaign
- U.S. Attorney's Office, E.D.N.Y.: Leader of three worldwide cyberattacks sentenced to 8 years for computer intrusion and access device fraud
- U.S. Attorney's Office, E.D.N.Y.: Leader of global cybercrime campaigns pleads guilty
- Daily FT (Reuters): Indian companies at center of global cyber heist
- Finextra: Bank Muscat hit by $39m pre-paid card fraud
- Finextra: Bank Muscat to recover $39m card fraud losses