Carding And Ways To Protect Yourself

Happy Klaus
5 min readJun 9, 2021
A person holding mastercard in dark
A modern looking credit card

Since the very beginning of humankind, if anything is happening, that is fraud. People used to steal ones’ hunt, and fight over to get others’ woman. We used to scam others with rotten food to have ourselves something fresh. Betray others to death so that we can take over their shelters. You name it, and we did it all.

What I mentioned earlier was only the image of the past. Besides, in the modern age, we didn’t stop doing fraudulent things to satisfy our needs.

Before digitization happened, there used to be pickpockets, thieves, robbers, and many more. Now we have got carders, spammers, scammers, and so on.

The past version of fraud and robbery was risky enough even to risk the fraudster’s life. But now, the fraudsters can get away with their wrongdoings without even getting traced.

In 1950, the first credit card was invented. Since then, the robbers came up with many easy solutions for robbing a person, such as stealing a person’s card data and using it to profit by cloning the card. Identity theft is the best suitable term for that, even though we now call it carding.

Before plastic money happened or even during the age of plastic money, there was also cheque fraud.

To prevent those kinds of frauds, banks came up with several ideas and solutions. The fraudsters weren’t sitting; they also did crack the security systems of banks to do scams.

The world got introduced to online payment gateways around 1994 to 1995, and the most famous Amazon and eBay happened. An era of paying online with card info and getting goods to doorstep started. Along with that, the golden age of fraudsters also began.

Back then, there were so many phishing sites that were claiming to provide goods by charging credit cards online. Instead of delivering the products, they started collecting the data, using it elsewhere and getting rich. And banks had no idea about this.

The fraudsters weren’t just phishing cards; they also generated the card info by following the Bank Identification Number ( BIN) sequence and several algorithms such as the Luhn algorithm. And they spam the card info into multiple eCommerce sites to come up with a valid combination of card info linked to a legit bank account. This method is known as software generating.

Banks and card providing companies were trying their best to prevent any financial threats and came up with many methods, such as zip attaching, Date of Birth, First and Last name, etc. And that wasn’t sufficient enough to prevent the fraudsters from doing fraud.

The fraudsters came up with an idea known as spamming; they started to send junk emails to their targets in terms of making a payment and then phishing the card data.

As of now, the carders have the accurate data of the cardholder along with the cards. They are now two steps ahead of the financial institutions. And there was no way to stop them.

But thankfully, the banks and the financial institutions came up with a solution for that, too. By which they will check the user’s IP address and browser for any blacklists.

But, the carders came up with something more dangerous. They started to use socks5 so that their IP can not get traced. They began to clean their cookies. They were ensuring a total safety measurement.

Whatever, we have seen so many evolutions in online usage of our financial data along with our credit card info. “Card number, expiry date, and CVV matching,” cardholder’s name matching, city and state matching, zip matching, SSN verification, date of birth matching, OTP verification, 3DS, to name a few.

The eCommerce or online payment accepting platforms were forced to use 3DS to ensure that the user is the actual cardholder. Besides, the payment gateways are now developing their system by the instructions of standard PCI DSS compliance. All of these are for preventing fraud.

All the safety and security systems should ease our fear, but there are no secured systems. The fraudsters invented even more powerful tools to do fraud. They are using some anti-detect browser and bypass the fraud detection system. They are fooling the 3DS (3D Security), VBV (Verified By Visa), MSC (Master Secure Card) by stealing the cookie of the authentic holders of the cards and using it in their anti-detect browsers.

It would be excellent if the story ends here, but the fraudsters are doing fraudulent things offline, too. They steal the card data from the magnetic stripe of your credit card and clone the data to a blank card. Here they get full access to your card, and they can use it anywhere they want.

Although the banks and financial institutions came up with many solutions for offline card fraud, there are still scams happening.

So, are there any ways to put a stop to all of this?

Yes, there are many ways to prevent these from happening. The first thing to do is with yourself. You have to be more cautious, which email you are replying to, where you are putting your card data, which links you are clicking, and which site you are allowing to use your cookies. If anything seems off to you, don’t proceed any further with it. Stop using public internet connections; start using trusted VPNs.

If we are cautious enough then our data may not be leaked. By any chance, if your card info got leaked because of your fault, inform your bank about the incident. Try to lock your card from your bank app. There are so many ways you can prevent yourself from getting reaped by carders.

Let’s say, somehow some carder used your card and pulled your bank balance to zero. What do you do now? The answer is, you call your bank and inform that of what happened. They will charge back the transactions and will put a hold on your account along with an investigation.

You are the one who can put a stop to all of this.

Credit: The picture has been taken from “Unsplash”

--

--