Transaction Spies: Fraudsters’ Secret Card Monitoring Techniques
Blog

Transaction Spies: Fraudsters’ Secret Card Monitoring Techniques

COVERT TACTICS UNVEILED

  • Fraudsters are finding ways to covertly monitor and take over victims’ online banking and card services accounts by exploiting banking and financial apps while leveraging sensitive PII.
  • The “Enrolls” Scheme: Cybercriminals stealthily enroll unsuspecting victims in online banking, gaining unauthorized access to their accounts for various illicit activities.
  • Anti-Fraud App Exploitation: Fraudsters misuse anti-fraud apps such as CardValet to monitor and control compromised cards, and then managing security features to carry out fraudulent transactions.

THE “ENROLLS” SCHEME

The “Enrolls” scheme involves fraudsters identifying individuals who have opened banking accounts associated with compromised debit/credit cards but have not yet enrolled in online banking.

Transaction spies image 1.
Example of a Telegram post explaining “enrolls”.
Fraudsters secretly enroll victims in online banking, gaining control of their accounts without their knowledge. They may leverage other sensitive PII, such as SSN or DOB that is necessary for the account creation process.
The purpose is for the fraudster to have more accurate account visibility, such as for transaction activity, and for account control. This control can extend to cashing funds out of the account via ACH, wire, or other means.

The two main ways a fraudster can obtain an “enroll” are:

  • Through sellers advertising cards that fraudsters can “enroll” themselves or access to already enrolled online bank accounts.
  • Compromising and registering accounts themselves.
Transaction spies image 2.
Example of an “enrolled” compromised bank account.
To the right is an example of a Telegram post sharing the types of information a fraudster can control, such as the current balance and correct billing address.
Transaction spies image 3.

HOW CAN FRAUDSTERS USE “ENROLLS”?

Providing access to online card services accounts; enrolls can be used for:

  • Reshipping Fraud: A common anti-fraud measure is the Address Verification System (AVS), which checks whether the billing address associated with the account matches the shipping address provided during an online transaction. A fraudster can modify the account holder’s billing address using the online card management tool, aligning it with the mule’s (or reshipper’s) address1.
  • Micro Deposits: Some online payment platforms (e.g., PayPal) use micro deposits as a card verification method. This involves processing one or two small transactions on the account holder’s payment card. To confirm card ownership, the account holder must enter the exact amounts of these transactions. However, if a fraudster gains access to the online card account, they can view these transactions and complete the verification process themselves.2
  • Transaction Approvals: Banks and e-commerce retailers may require SMS or phone verification to approve certain transactions. By updating the account holder’s contact phone number through the online card management tool, a fraudster can redirect verification requests to themselves, allowing them to complete the transaction undetected.3

ANTI-FRAUD APP EXPLOITATION

The “CardValet” scheme involves fraudsters creating an account for the compromised card in an app called CardValet.4 Card Valet is an app designed to manage and control transactions on your payment card(s).

Transaction spies image 4.
  • Fraudsters exploit the app’s security features by creating accounts using victims’ PII.
  • Cards labeled as “Valet” advertised on the Dark Web are issued by financial institutions that offer the app to their cardholders.

Fraudsters leverage the app’s security features, such as unblocking cards and transaction monitoring, for illicit activities.5

CONSIDERATIONS

  • The schemes highlighted here – “Enrolls” and misusing apps such as “CardValet”— demonstrate the evolving tactics fraudsters use to secretly create victim accounts that allow them to monitor and ultimately defraud the victims.
  • The Dark Web plays a pivotal role in such schemes, facilitating the dissemination of compromised PII, as well as the sale of the compromised payment cards.
  • Financial institutions should consider implementing controls to mitigate these threats, for example, requiring two-factor authentication for new online account creation and CardValet registration or notifying customers when such accounts are registered.
To read more on enroll fraud, see our blog here: https://q6cyber.com/wp/blog/online_card_enrollment_a_fraudsters_handy_tool