The transcription discusses the security of mobile tap-to-pay systems and a large-scale criminal operation exploiting them. Tap-to-pay uses tokenization and unique cryptographic codes, making it more secure than traditional credit cards by never exposing the actual card number during transactions. However, a sophisticated organized crime group has innovated to compromise this system. They operate a phishing-as-a-service platform called "Lighthouse," which provides tools for mass smishing (SMS phishing) campaigns. Victims are tricked into entering their credit card details on fake websites. The key innovation is an automated "wallet provisioning" process: the stolen card details are instantly displayed as a virtual card on a screen, which a fraudster's phone camera scans to add the card to a digital wallet like Apple Pay. The scam simultaneously bypasses two-factor authentication by tricking the victim into providing the verification code. This enterprise-scale operation, described as "phishing for dummies," is highly automated and vertically integrated, leading to massive fraud estimated at over $1 billion and the compromise of tens of millions of payment cards worldwide.
All it takes is once, and that's what these actors are counting on. It's a numbers game. For the last two years or so, Ford Merrill has been investigating a sprawling, criminal enterprise. It is so sprawling, Scott, as to be kind of hard to find a way into explaining. So, to start, I want to talk about tap-to-pay on mobile phones. Okay. I'm assuming you use tap-to-pay on your phone, Scott. I do. NFC is great. I love having your credit card linked to a phone. I forget my wallet all the time because I am old and forgetful. Me too, but I always have my phone because I'm addicted to it. It's very useful. Tap-to-pay is interesting. When you tap your phone on a payment terminal, the device isn't sending your real credit card information. Instead, it's basically like proving to your bank that this specific phone is authorized to act as your card. The phone and the terminal do a little handshake over NFC, and then your phone sends two pieces of information. First, is a token. Token looks just like a normal credit card number, 16 digits, but it's not your real number. It's a device account number created when you first add your card to Apple Pay or Google Wallet. It only works on that device. The merchant never sees the real number. They just see that token. If someone steals just the token, it's useless on any other phone. The token is bound to the device and validated using keys, stored inside of the phone's secure hardware. This was the whole pitch when they brought this stuff out. Your credit card number will be protected in these NFC transactions. It'll be more secure, even online payments using something like Apple Pay or Google Pay. It will be more secure because we are not using your credit card number. If there's a compromise to their payment database, it won't affect you. Exactly. Because the second thing your phone sends is this little piece of cryptographic data. That's created inside of your phone's secure hardware. And that little cryptogram is unique to the actual transaction. It's time-limited, and it's mathematically tied to the device's secret keys. Those secret keys are issued to the device during this process. We're going to be talking about a lot this episode called Wallet Provisioning. That's when you add the card to your phone, and they're stored in hardware that the operating system can even really access. So, the phone sends the info to the terminal when you tap it to pay. And that sends these two little bits of information through the normal payment rails. The processor, the card network, and finally, it all gets to your bank. The bank checks whether the token belongs to the card holder. And whether the cryptographic code matches what the device should have produced based on those secret keys. If all of this lines up, the bank says cool, and it approves the transaction. This all happens super fast. And during this process, no credit card number, as you mentioned, Scott is ever exposed. And that one-time code can't be reused. That's tap to pay. Now, as I understand it, and as you said, and basically every way that matters, this is a lot more secure than a traditional credit card. Even if someone skims all the info from that transaction, they can't really do anything with it. They don't have the phone, the code was time sensitive, therefore it's all more secure. That's not really the case with the normal credit card number. They need all these extra layers of fraud detection, and prevention in case you were to lose it. If the number gets used on a different continent, 30 minutes after you last used it, where you live, a bunch of alarms go off. The insecurity of the classic credit card is so bad that they use probabilistic modeling and behavior modeling to try and make them moderately secure. But there's nothing going on there that's actually making them secure. They added three extra digits, what, 20 years ago, to the back of the card. Fraught systems with tap to pay still watch for weird device and spending patterns. But the cryptography of all that does way more of the heavy lifting than it does for like Meg, Stripe, or just like the plain card number payment. Tap to pay can afford to be a little more loose. So, we get to our subject this episode, and maybe as an exercise, we're going to imagine exactly what you would have to do to compromise mobile wallet tap to pay at any kind of scale. First, you would need a system for stealing the credit card info, like the original number in the first place. There's a whole world of solutions for how to steal credit card numbers. Traditionally, like a very common one has been smishing, like spam text messages that trick people into going to a fake site, filling in their credit card info. If you really want to get nasty with it, you could spoof an e-commerce site that people might willingly go to on their own. And then, I don't know, maybe promote your fake version of a real e-commerce site on just to pick a random example Facebook. You can listen to our episode about what percentage of Facebook's revenue is the kind of scam ads I'm describing right now. Not to mention some physical tactics, like skimmers. Yep. They have massive issues with skimmers at gas stations and ATMs that are in public. You know, the classic old-school way of stealing credit card information. The mobile top to pay prevents against with all that cryptography. Then, this is where you'd have to get really innovative. Because, as we mentioned, traditional credit cards have a robust security layer for fraud detection but tap to pay less so. But getting someone's credit card number that you've stolen added to your mobile wallet on a phone you're controlling without their consent would require a custom built automated software that works in concert with the spoofed e-commerce site. To, when they give the real credit card info, auto add that credit card to a phone wallet you control. You might, for example, do this by displaying the credit card number on a fake credit card on one screen and then having a phone with its camera open over here, scan that fake credit card to upload the information basically instantaneously. At which point, two-factor authentication is going to occur. The fake e-commerce site that they're staring at that they think they've uploaded their real credit card information to might tell them a lie like your bank requires a code to approve this transaction. They get the two-factor authentication code to add their credit card to a new wallet. Maybe it auto fills on the fake e-commerce site and boom, they have then unknowingly verified someone else's phone to be able to spend money on their credit card. It's quite ingenious. It's elaborate. Yes, elaborate. The idea of setting up all of this physical infrastructure, having a virtual card simulator, because chances are, like I know, when I add cards to my phone, it wants the card to match the style of card it is. So I wonder if they don't have fraud preventions in there to be like, well, this doesn't actually look right. You know, the numbers and stuff check out, but the card doesn't match the aesthetic that we would expect. You know, there's probably catches like that in there that they've had to deal with. So when they read your card and they're going to have to look up and find out what kind of card it is and immediately render something out that then a phone scans in and adds to a wallet. Clever. It's very clever. This wallet provisioning process is an innovation that kind of like traditional smishing and credit card fraud never really had cracked. And I'm letting this all sound as complicated as it is to give a sense of the scale of the enterprise that are subject to this episode, Ford Merrill has been researching. And I have to kind of give them a bit of a compliment. They have been so innovative and so creative over the years and months that we've been tracking them that they've continued to adapt and pivot. It's called the smishing triad and a main player within that a fishing as a service developer called Lighthouse. To me, Lighthouse looks a lot like a vertically integrated business, specifically like enterprise grade software because that whole software stack that I describe from thousands of fake e-commerce site templates through to this never been done before wallet provisioning process. All of it. That stack, they license it out to people wallet provisioning is one of a handful of features inside of Lighthouse that have never really been done at scale in these kits. Lighthouse is innovating in weird new ways that as we discuss this episode are just getting weirder. This is the second recent story in which a giant Google lawsuit plays a role. They issued a lawsuit against 25 unnamed John Does. They highlighted more than 1 million victims across 120 countries between 12 and 115 million US payment cards compromised 200,000 fraudulent websites linked to activity of Lighthouse with about 25,000 fishing domains and an estimated $1 billion US in fraud losses tied to Lighthouse enterprises. Google's own words the lawsuit described Lighthouse is a fishing for dummies kit powering a quote relentless smishing operation. The population of the USA is roughly 340, 345 million. So when you start talking about upwards of 100 and 15 million credit card details. It's insane. You're talking about a third of the country. And if you assume a third of the country is children don't have credit cards, you're actually talking about like half of that country. That's that's that's wild. Yeah, it's enterprise great software is what it is and we talk about this in the interview. I love I love you know, we've talked about this a few times in multiple episodes just how cybercrime is becoming its own enterprise and its own market niche. 100% and this is this is one of those things where you've got a business that's now spending and research and development developing new products and services to bring to their market. The real question that I have though. Do you think they bill like a monthly flat or do you think it's a percentage of take. Sure, is it a commission or is it like we take 15 or 20% of like all revenue generated or is it something like just give us $12,000 a month. I'm sure they'll take your money if you want some tools for smishing people. Yeah, ready to jump in. We are, but I think there's one last thing we have to do. I think this is our last episode that comes out before the holiday season. You are correct. So I think we just got to wish a big happy holidays to all of the fans and listeners of the show. We thank you so much for your time and the attention and we hope we keep you company when you do all the fun things in life that we all listen to podcasts when we do. And we love to see the comments of people watching their dishes and mind their grass. Lots of commuting. I think aside from that, there's been some requests for a hotline hack. So stay tuned. That's going to come out sooner than you might think. Well, thank you so much for spending this year with us. It means a lot to us. We really appreciate it. We're excited for one last one this year. This is a wild one. I got on the horn with Ford Merrill, Senior Director of Research and Innovation at Secolines, part of CSIS Security Group to talk about Lighthouse and the Smishing Triad here on Hacked. [Music] Ford, good to get to talk to you. This is a wild story. We have enterprise grade software, an organized crime operation. I have to think even with all of your experience in this, the years of research, you must still get struck by this feeling of like, wow, this is pretty out there. Yeah, I mean, when we started looking into this, when I started looking at it around August 2023, we really had a huge revelation and we were shocked to that this was the first group we had ever seen using digital wallets for fraud. Apple wallet and Google Pay. But at every turn, there have been sort of innovations that also just kind of leave us a little bit flabbergasted or just impressed at the ingenuity and creativity of these threat actors. So at super high level, you've been researching this organized crime syndicate built around these fishing scams for years now, long before any of us in the public had a name like Lighthouse to kind of point towards. Super high level, what is Lighthouse and where did it come from? Take me through this thing. Yeah, well, maybe we even zoom out before above Lighthouse at a higher level, right? What we've been looking at is sort of Chinese smishing and what that is is like all these package delivery or read delivery messages people have been getting all the toll road scams that have been prevalent in North America. They've also done things like government impersonation tax refund scams and various other lures, but it starts with a text message or an I message or an RCS that you receive telling you to, you know, click this link to have a package delivered or pay a small toll find something along those lines and subsequently the victim will lose their personal information, their credit card information and a the most important and interesting sort of innovation from them was the ability to do real time to factor or multi factor authentication bypass. So they'll also recover the victim's text message or SMS based OTP code and that will be used for other types of fraud that require multi factor authentication bypass and so Lighthouse is a fishing as a service developer effectively that makes software to enable people to do this Google in their complaint I guess that we'll talk about in a bit called it sort of fishing for dummies. You pay a couple hundred dollars a month you get the software to run these smishing and fishing sites they're all templated and skinable so you can just pick whichever country in whichever organization you want to impersonate whether it be United States Postal Service or you know DHL or FedEx or whatever it is. And then you point a domain at the thing and start spamming out and that's all you have to do. I mean you alluded to this but the thing that struck me about this is just how industrial it feels there's this enterprise equality to it I think Google says lighthouses if they hit about a million people 120 countries up to 115 million credit card numbers. You know profits and the billions I guess my question is like again super high level like where does a cyber crime operation and as and not legal but basically just a software as a service industry project begin and is that. Is that boundary that binary even real at this point well I mean I'm not sure. I really have a great answer for that other than just to say I mean definitely we've been sort of shocked by the scale of these operations and sort of totally agree they're industrialized they're automated they operate like a business this whole ecosystem. It's sort of evolved just like it would in a capitalist society in the sense that certain actors in this ecosystem specialize in very specific things so the fishing as a service developers all they do is make the software that you run on the website. There are people that do nothing but specialize in spam operations for text messages. I messages so on and so forth there are people that specialize in the money laundering side of things. Just so many different aspects that that yes this is organized crime it is sufficiently advanced at this point and where it really starts and when it transitions to become like you know at that level we now determine that is organized I'm not sure kind of the inflection point but it's there and it has been for some time. I dig into the tech but this one last little thing just for you personally like what was the thing or moment that pulled you into all this like what did you see that made you realize this wasn't just spam text messaging as were used to it kind of take me through that personal story for you. At my day job I've been involved in a lot of work around anti-fishing I developed an anti-fishing platform where we basically track all the fishing sites in the world and we do mitigations and take downs and stuff like that for customers but we were tracking in 2023 just this massive spike in package delivery fraud all the sudden we were just seeing tens of thousands of domains targeting United States Postal Service. And we were like you know this is the largest single campaign we've ever observed right and we started looking into it and we ultimately kind of got lucky because some of the threat actors left some of their fishing kit source code behind that was. One do you are also known as law one who would later go on to create lighthouse and so we had this very early version of his fishing kit we're able to identify him identify his telegram channel and start to kind of look into peak behind the curtain into this whole ecosystem. And from there it just kind of snowballed I mean we saw that they were involved in the digital wallet fraud that part of what these fishing kits enabled was the bypass of two factor and then subsequently taking the victims card and putting it into a wallet and that for me was the point I was like okay this is something really big. And I started putting putting together a presentation deck about it started talking to some of our customers about it and you know over the years it just continued to snowball and grow and grow. I want to know more about the digital wallet that wallet provision layer I think most of us think of like okay what is fishing someone sends a text they trick you into giving the mere credit card and they go buy sneakers with it or whatever when you first realize that there's like there is a meaningful innovation here this wallet provision layer explain that kind of whole concept to us. I mean kind of from the start like when you click on this link to begin with the actors already do some pretty important controls to make sure you're not like a security industry scraper or something like that so it's going to be geofence to the IP the geolocation so if they're targeting United States Postal Service you'll need to come from an American IP but even more than that they also require you to be on a mobile user agent so you have to be on a phone to get the real fishing page. And then once you do it'll be incredibly authentic looking version of the site they'll ask you for the personal information you know in this case to make sure your delivery can be scheduled or something they'll ask you for a small payment of like 30 cents. And this payment is actually never going to be charged to your card at the time it's just a reason for you to input the card information and then subsequently once you put your name and card number and expiration and CVV you're going to start spinning and presumably you think that you're waiting for like the card to be processed or something like that but on the back end. The threat actors have like a visual representation of your card literally like an unbranded imagine like a black credit card that has no branding or anything it just has your name and your phone number on it and what they do with it is they have a phone ready to go on the back end with like Apple wallet or Google wallet open ready to add a card. And when you add a new card to your wallet the first thing the device does is say okay can I use the camera show me the card and so they would scan the picture of this card that they've automatically generated the kit off the screen with the camera and the phone doesn't know it's just like a computer screen version of the card. And this rapidly provisions the card number into their phone so they don't need to type the numbers in which is important because you the victim are waiting and spinning and then immediately Apple will prompt them or Google will prompt him and say okay if you want to add this card you need to complete a two factor step select. Do you want email or phone and they'll pick phone and then you the victim will get advanced to the MFA bypass page where now they'll ask you okay we just sent you a two factor code please. Input it here and you will also have just receive that message with the code on the same device most likely this is part of the reason that they require you to be on a mobile user agent they want you to be on the phone when you visit the site because you're most likely to be on the same device that will receive it. And on top of that if you've ever used the feature on like an iPhone or a Google phone where it can automatically populate the two factor code you just received from the message in the background to whatever form you're on. The victims also use that right so they're on that page on the fishing page that's asking for your code as soon as you receive it your iPhone will tell you hey auto fill from messages and you just click that button it inputs the code and you know that that's it they're able to complete the provisioning of your card in their digital wallet and you've effectively told your by your financial institution that you trust that device to spend that card anywhere and no MFA will ever be needed again. So that was kind of the genius unreal. Yeah of the of the digital wallet angle. So they do all of this while you're waiting you input the two factor the indication that you have basically verified their device as being your device and they can go spend money on that device. Do you have a sense of and I appreciate the scale of this is so significant that there isn't any one answer but now that they have a device loaded up with your card what happens immediately after that where does that device go. So what do they do to try and juice as much money out of this as humanly possible. So yeah we know a lot about how this works. So in the beginning when we first started seeing this what was really interesting is actually they would wait almost two to three months before they did anything. And part of this we believe is they were worried about sort of the risk control signals that it would give to a bank if suddenly a random device added a card and then just started spending right away. So in the in the very early days they would add these cards and they would wait a long time to spend them. But nowadays you'll be lucky if they wait like a couple of day you know one to two days maybe three days or seven. But then they have a lot of different ways to launder the money and get the money out of the card because if you can imagine when you have a card in a digital wallet and you're just a legitimate user I mean there's a lot of ways you can use it you can tap to pay for things you can buy things online in apps. You can also tap to withdraw from ATMs in some countries and with some banks. So there's a lot of immediate options available. And one of the things that you might think of doing is just go to the store and tap to pay for something and that did work a lot in the early days. But as time goes on the banks get better and better about their risk controls and all this kind of stuff so imagine if you're a threat actor sitting in China and you have a lot of American victims cards on your device. If you go to the store and just try to buy something traditionally probably the geo controls are going to block you because you're not in the right country. But even if that purchase did go through you're on camera right and eventually that transaction will be reported for fraud there will be a charge back of some sort and that merchant now has you on camera which is probably not a good look. So one of the first things they started to do was look to what we call merchant account laundering. And the way this works in the online version of it is you will create or the threat actor will create a fraudulent account with something like Stripe or PayPal or Zettle or one of these online sort of credit card acceptance or payment provider solutions. And then with their fraudulent Stripe account they will generate a fraudulent invoice for something like let's say a short term room rental on Airbnb $500 or whatever. And then they will go to that invoice with the device that they have with the victims card loaded and they'll use the pay with Apple Pay function to pay themselves the Stripe invoice and then that'll go to their merchant account. And then that is an interesting angle but it's not without its challenges because merchants are used to credit card fraud so they withhold money for a long time and it's not the ideal way to launder but it is a way. The other thing we've seen is that some of the threat actors will obtain physical point of sale card terminals so just like if you run a business and you need to accept credit cards in person or tap to pay in person you just get like a square device or some other kind of like physical terminal. They would obtain and collect a lot of terminals and then they would have you know 100 phones with five cards loaded on each one so they got like 500 credit cards and they would generate fake invoices on like a little point of sale terminal machine and they would just tap to pay with the victims cards over and over again. And this was another form of merchant laundering physical merchant laundering but the most interesting ones and probably the ones that have driven the most losses and been most impactful are physical goods purchases through the use generally of mules and then the other one is gift card purchases and why those are so dangerous is because once those physical goods or those gift cards have left the building. Somebody is guaranteed to take the loss it's either the merchant that sold the product the bank that issued the card or the victim who had the card with the bank but somebody is going to lose their money and you can't really put it back in the bottle. So those are are sort of like some of the key ways they do it before I jump into like the the mule thing and the NFC relay I mean do you have any questions or should we talk a little bit more about that maybe something's not clear yeah my next question was going to be to explain the mules to me because as I was reading through this there's something that hits very emotionally different for that mule layer than the other ways that they're laundering this money is a real people who think they're doing like a temporary job. And I guess I'm curious help people understand how that whole process works do you have any insight into how the people behind to see those mules tell me about them yes or our visibility into this sort of mule process is a little bit limited because we we don't actually go through the process of like trying to become a mule ourselves and get involved in it we just observe and see. Kind of from the discussions and the advertisements that they have but we generally believe that they advertise on various platforms tiktok Facebook you know add sense other kind of social media probably on like we chat and other forms and they're just basically looking for people who want to make extra money by doing sort of you know small tasks or whatever. And what they'll ultimately be signing up to do is buying things in physical stores mainly gift cards but also sometimes luxury physical goods or other products that are easily resellable. And the way that they'll do this is they will be instructed to to have a certain type of phone usually it'll be a Samsung galaxy phone it's necessary to support the NFC relay story. And they will be given like an APK or an Android app to download and when they open this app it will basically just provide them credit cards to use that work for tap to pay. So the way this kind of works fully is they will usually be in close coordination with their mule handler or the operator and that person will be operating I like to say behind the curtain right they might be in China they might be in Southeast Asia they might be somewhere else. But effectively they're they're sitting somewhere else with stolen cards that have already been uploaded onto digital wallets so they have a lot of iPhones or Android or whatever with these cards on them. And they will have another device and Android device that is running generally I think it's going to be rooted and it's running the server version of this NFC relay software. And when they touch those two devices together the wallet device with the card on it and their Samsung running this custom software it will relay that NFC card to the mule that has the client side version of that software running on their Android phone in the field. And so now the mule can basically just walk up to the point of sale terminal and tap to pay for whatever it is using the card from behind the curtain from like 10,000 miles away. And it works just like a real tap to pay transaction because actually effectively it is a real tap to pay transaction it's a perfect relay. And yeah it's that's basically what they do they just take stolen cards they add them to wallets all day long they hire mules to go out into the physical places to buy the things that they want. And the mules go up there and just buy gift cards are so on from like automated kiosk or self checkout kiosks and they will generally then scratch the codes off of the gift cards take pictures of them and then send them back to their mule handler who will cut them in on some of the money. Unreal. What if we told you the one tool could secure hundreds of applications? Trelica by one password gives IT and security complete oversight of their sprawling landscape of SaaS apps where the company managed or unmanaged shadow IT. Trelica by one password inventories every app in use your company then pre populated app profiles assess software as a service risks letting you manage access optimize spend and enforce security best practices across every app your employees use. Managed shadow IT securely onboard not for employees and meet compliance goals Trelica by one password provides a complete solution for SaaS access governance and it's just one of the ways that extend access management helps teams strengthen compliance and security. We here at hack to use one password and we think that it might be a good idea for you to check it out. Take the first step to better security for your team by securing credentials and protecting every application even unmanaged shadow IT. Learn more at one password dot com slash act that's one password dot com slash act so much of this seems as though I can imagine it being automated. There's stages to this process that I have more questions about that seem like you could have this running in the background on a computer somewhere. That seems like it would require a ton of human labor like you are just coordinating with a small army of people running around doing these transactions running these fake cards. I also saw a number it was light had boasted lighthouse boasting like 300 plus front desk staff worldwide I'm not sure what that means. What does the scale of this mean to operation like what should we visually be picturing is there are there call centers full of people running this is this decentralized like what does this workforce look like well. We don't know exactly in terms of visually what it looks like but some of the things we do we know the spam centers or the spam operations. You know we've seen racks of iPhones and Android says like 100 to 200 phones deep on like a rack that will have let's say 20 phones wide and five phones deep and one operator is sort of just visually managing like 100 phones at a time and those are all being automated to blast out like I messages or RCS and maybe at some point one of the phones will get like banned by Apple or something and he'll need to pull it out of the rack reset it. You know set up a new eye cloud account on it put it back into the automation and keep it going so that's you know imagine there's there's many actors like that on the spamming side. On the phishing side I mean and just in this ecosystem as a whole I mean just individual channels for just for instance la Wang who sold lighthouse his telegram channel had something like 21,000 impressions or views and almost like five or 6,000 people in it by the time it was the first one was shut down by telegram. We believe you know we track 10 major phishing as a service actors just like la Wang and so if he has 6,000 in his channel we know some that have 10 and 12,000 in their channel I mean tens of thousands of Chinese speaking individuals that are in these groups. And so yeah we believe there's easily tens of thousands of people involved in in every aspect of this fraud and some of them are going to be smaller operators that they just buy access to the software they pay a spammer to send their messages and maybe they target. You know the US or Canada or whatever their little geographic region is and they may do it for their own gain and collectively when you start to add up all these small actors it's a tremendous amount and then we've also seen evidence to support there are some groups that are truly organized crime in the sense that they're just openly advertising that we do it all from spamming to. It's the point of sale laundering to you know phishing platforms to giving you data to target your fish like everything is. So it's pretty big when I was first reading about it I mentioned this earlier but it kind of drew parallel with like software as a service but it the more you look at it the more it's like yes there's software as a service and enterprise grade software when there already exists a marketplace. There's this much larger marketplace of people that are trying to spin up these types of operations someone can say oh I'm going to target this part of the world with this type of messaging oh I'm going to target this group with these types of lures. How does that how does that fester like where does that come from is this all just growing on discord channels on the internet like is there a top down way of thinking about this like how did this grow in the first place. Well I mean when there's money to be made people are interested in making more. I think you know Lao Wang who who authored a lighthouse and then subsequently or are also darkula. We're kind of some of the OGs when it comes to Chinese smishing operators and they develop probably some of the first really sophisticated kits that could do these real time SMS OTP bypasses and be used for digital wallets. And so we're not exactly sure who really invented this sort of recipe with the digital wallet cash out angle in the real time OTP bypass but it was probably one of them or somebody that they were close to or inspired by. And then you know once they started having a little bit of success doing this I think one of the things they quickly ran into or realized at least at that time before a lot of it was automated was. Well I mean one person can only sort of put so many cards in wallets at a time right like if you send out if you send out a blast of spam and you have a thousand victims rolling in and you know let's say let's say 50 of them are putting their cards in at the same time and then you need to provision those wallets like one person can't do all that so there's a lot of. Of loss that you know fish basically fish catch that you're losing by not being able to have enough hands on the problem and so they were like hey this is free money that we can't monetize we could sell this software to a service and sort of like. Avertise it so that other people can get in on this action and we can happen to profit from from that activity to and what was really interesting is in the early days we believe almost all of these kids were back doored so their customers would pay them a fee every month to use the software and the service but they could then come behind and just scoop up all the card information and the victim information anyway now granted or granted. They couldn't tokenize it once the victims no longer on the hook and they don't have the MFA anymore right but they could still use that card data for like card not president fraud or follow up wishing or social engineering things like that and so it's just really interesting they were like double dipping by selling the software their customers and stealing. And why would their customers assume privacy when they're purchasing privacy infringing software in a sense correct. You mentioned them a couple times law weighing the like the author of lighthouse what do we know about them tell me about well what we know is is kind of limited in terms of real term personal attribution but we know they've been around since February 2023. He originally provided sort of tuition not just the software as a service which he certainly did but he also offered people an ability to be under his apprenticeship and learn how to create and modify these kids. And we believe he was he apprenticed somebody who he called the young lady which we believe later went on to become an actor that was known as Chen Lun and she created what he called one of the most advanced kids his students had ever made and it was a gov.uk tax based fishing kit at the time. But he was sort of like I said a visionary and OG he had around 17 brands that he target with his targeted with his original kit that we call version one but his most prolific victim was the United States Postal Service and the American people through the use of United States Postal Service Package Delivery Lovers by far his most popular kit. The other thing that he specialized in and still does specialize into this day is fake shops so he supports a workflow that instead of sort of getting a message and needing to log in and do something and lose your data. He will allow you to set up a fake shop and e-commerce site selling anything you want it could be toilet paper or dish detergent or electronics and it looks just like a real e-commerce site and when the victim goes to check out for this product that they think they're buying they literally just lose their personal information they lose their card information and then they lose their OTP again because they think they're doing that for the payment validation. And these are a lot more sinister in some ways because they have a lot more staying power because no messages are sent out not a lot of people report them. They also don't require you to receive a message and click on something to be victimized you could just be searching for something you want to buy online and see this e-commerce shop that looks to have a good deal. And they advertise these sites on AdSense, like on Google AdSense, on Meta Platforms, on TikTok, you know I'm sure you've seen the news that Facebook had like $18 billion in revenue from scam advertisements like things like that are driving people towards these fake shops where they then self victimize. So that was another big part he was kind of a pioneer in that fake shops space as well. And he went on in August of 2024 he would later he would launch the kit that was would be known as lighthouse and for a number of reasons he wanted to modernize the code base he wanted to make it more modular basically just improve functionality across the board. And when lighthouse originally launched he only targeted 17 brands with the old kit within a month he targeted 29 brands and a month later he started targeting 63 countries and each of those countries would often have multiple brands so just kind of like the new kit skyrocketed his ability to scale the brands for his customers. And yeah we believe he was very successful for you know since early 2023 and finally Google released this civil action this lawsuit against does one through 25 related to lighthouse and he's subsequently shut most of his telegram stuff down gone dark it looks like a lot of his infrastructure got knocked offline and so he's probably looking his wounds and rebuilding would be my guess. Yeah since you brought it up this is the second story in his many months about Google being involved in a lawsuit with alleged cyber criminals we report on their lawsuit against a group installing malware on these cheap consumer electronics. This lawsuit it you know kind of frames lighthouse under Rico basically saying like this is an organized criminal enterprise you alluded to this a second ago in terms of him kind of going off and licking his wounds but like from a research perspective. Why does Google do these lawsuits and what role does legal action play in disrupting stuff like this like is this just whackable or do these lawsuits have an impact. Well I mean first off the disclaimer obviously I don't work for Google and I'm not a lawyer so it's hard for me to kind of do anything but speculate but I can do a little bit of informed speculation anyway because of my knowledge on sort of this subject. I think this action or this type of action taking civil action against a cyber criminal actor is really interesting obviously we also saw it in the past with Microsoft using it to obtain default judgements and then go after like C2's of known malware or botnets that we're causing a lot of problems for windows users and things like that. And I think one of the more interesting parts of it or ingenious parts of doing it in a civil way is that in a criminal case you really have a high barrier like a for proof that you know you need a lot of proof and it all has to be proper chain of custody and everything is really a high bar to prove somebody is guilty and then you have the jurisdictional problem where if these actors are sitting somewhere you can't really reach them or you don't have jurisdiction over them. That becomes hard to do a criminal thing and then like you said with Wacomal well if you do get a criminal action against somebody and you arrest some folks. I mean there's plenty more people that are going to pop up and so you're going to have to rinse and repeat that more expensive process over again. Whereas with the civil action you can file a suit against these folks in a jurisdiction that's relevant for you and almost 100% chance they're never going to come to defend themselves. So you will win by default obtaining a default judgment and then you can take that thing to hosting providers domain registries domain registrars all that sort of stuff and say hey we obtained a judgment these actors are on your platform doing bad things and we would like you to take them down. And most legal departments are going to say hey to avoid any extra liability or any chance that we get caught up in this thing it's you know they have a court order we need to take this stuff down. So I think at least in terms of disruption even though it might be temporary it does cause pain and impose costs for these threat actors. And to some extent it sorts it starts to limit their horizons right if they know that they can no longer use a hosting provider that used to be friendly. Then they'll need to look for another one and as these things continue to come and they get shut down from place after place and get run from provider to provider. Eventually they'll be left with sort of no other option other than the bullet proof posters the bottom of the barrel stuff that has zero reputation. And those become easier to block and automatically list stuff is suspicious from so I do think it has a positive impact and it is and it is a good approach. There are trade offs with it right. Tencent I mean on that note. It seems like a pretty large percentage of these like the domains linked to this we're coming from Tencent and Alibaba networks. Those are two of I believe the first and largest listed companies in China. If big tech companies in China ever did cooperate with say US takedowns lawsuits like this how much of this ecosystem actually would collapse. And how much of it is again just to use that metaphor is just whack a mold that's going to pop back up somewhere else. Well as far as I know Alibaba and Tencent at least do respond to some complaints and do take some action on them although they tend. I don't want to say malicious compliance but they tend to do it in a way that sort of. If you could drag your fetus much as possible and require as much information to make the process as painful as possible for a reporter to actually get something done. It seems to be the way they handle these complaints at least that's been what I've heard from folks who actually try to get these taken down and we also submit data to clearing houses that try to get these things taken down. So we've had sort of some of that experience as well. Yeah I mean a vast majority is hosted or so many of them are hosted at Alibaba on Tencent that's for sure. And oftentimes I mean so many of them are also protected behind cloud flare free accounts right so there's you know there's a bit of a tech enabler as well with cloud flare. But that being said you know if cloud flare was to stop offering protection for these proactively and they can make a good argument that hey you know we potentially it's not always possible for us to identify these things proactively. And I do know that they are responsive to abuse requests they have an API for that kind of stuff so I don't want to you know I'm not trying to throw them under the bus here. But you know I think if Alibaba and Tencent did something about this it would make a meaningful impact. Again you know the actors probably would just shift somewhere else to another hosting provider and just continue to do that until they've been chased to the bottom of the barrel. E.D. is more commonly think and simpler to treat than ever through him's you can connect online with a license provider to access personalized treatment options. Discreetly and on your terms through him's you can access personalized prescription treatment options for E.D. like hardmints and sex arcs plus climax control if prescribed. You shouldn't have to go out of your way to feel like yourself him's brings expert care straight to you with 100% online access to personalized treatments to put your goals first. To get simple online access to personalized affordable care for E.D. hair loss weight loss and more visit hymns.com/hacked that's hymns.com/hacked for free online visit actual price will depend on products and subscription plan feature products include compounded drug products which the FDA does not approve or verify for safety effectiveness or quality prescription required see website for details restrictions and important safety information. That's hymns.com/hacked Jordan is a former cat owner I know you're a current cat owner you could often hear him on this show what is the worst thing about having a cat the worst thing about having a cat is the litter box. The answer to this question this time old question is of course our sponsor this episode boxy the pro in boxy pro stands for probiotics which stops the bacteria that causes odors so you never have to smell your litter box ever again all you do is hop off the litter and you never have to dump out the whole box amazing clumping power makes the scooping easier and nobody likes dirty litter. If you're tired of switching litter is looking for the one get boxy at boxycat.com that's B O X I E C A T dot com it's the last litter you'll switch to and you can enjoy 30% off with code hacked at boxycat.com/hacked I'm curious to go back to the groups themselves a little bit and this feeling I got in reading through this story of like growing ambitions. You know the starts out and it feels kind of familiar it's the you know the postal service lure it's familiar stuff and there seems to be this escalation of like you've got card theft kind of moving into like even bank logins there was stuff about brokerage accounts yes there's a real sense of like we are climbing the ladder that is the western international financial system what should we take from that are they just truly ambitious are they learning like what's what's going on. I think it's a combination I mean they're they're ambitious for sure they they want money right they they are financially motivated and they've been to their credit and I have to kind of give them a bit of a compliment they have been so innovative and so creative over the years and months that we've been tracking them that they've continued to adapt and and pivot you know when they started with NFC relay I mean first off they invented digital wallet fraud I mean they have been so innovative and so creative over the years. First off they invented digital wallet fraud I mean it's crazy enough right and real time OTP and SMS bypass to be able to facilitate that's crazy enough. But then they basically invented NFC relay the ability to relay an NFC payment a tap to pay payment around the world and that's like mind blowing levels of nobody thought that was possible until they invented it and then they learned how to scale it and use it. Even on top of that now they've got technology that allows them to do NFC relay multi casting so a single user behind the curtain with one device. That's operating as a relay server and cards that he touches to that device can now support not just one mule operating in the field but it can support 20 or 30 or 50 or however many mule simultaneously. And because it's so clever how they've created it because tap to pay is a one time token transaction where you can't replay the token. If one of those 50 actors that's receiving that card taps to pay for something all the other actors temporarily lose the card on their app and then as soon as that transaction is completed all the other actors receive the card again so it's ready to go. And so you know things like this I mean first they hit you with NFC relay and then they come with multi casting and it's not even a couple months after they just invented this tech. And then to your point about banking and brokerages as the banks have gotten better at protecting against digital wallet provisioning so in other words the process of them adding your card to their device that has gotten harder for them because the banks do receive some interesting controls and data. From Apple and from Google that give them some ideas about risk levels of that device and all sort of stuff and they're starting to get better at preventing these malicious wallet provisionings so the actors have also built in a system that will automatically tell them which cards they should automatically reject and which cards they should bubble up to the top and prioritize because those will be the ones with weaker controls like smaller credit unions or smaller banks instead of the mega banks. And then as provisioning continues to get harder and harder and they scrape the bottom of the barrel they start using these tools that are perfect for real time fishing and MFA bypass to do things like account takeovers where they'll take over the victims paypal account or more interestingly lately and more saddening lately is brokerage account takeovers. So the way this works is you'll you'll get a text message that like hey your Charles Schwab account has had some suspicious activity you need to log in and do something about it. And it will be a fishing site that looks exactly like Charles Schwab they'll take your login information you'll give them your two factor or your multi factor and they will log in and now they own your brokerage account. Now you might have a million dollars in there or whatever investments you have in there and they can't take the money out in terms of wiring it out of the account because the controls are too good for that but what they can do is effectively liquidate all your positions and buy Chinese penny stocks or Chinese IPO stocks that they already own in their own personal accounts or their own criminal accounts offshore. And as you are as you are buying those penny stocks they're selling against your order flow so it's like a twist on a classic pump and dump where they used to have to convince you to buy a penny stock now they just take your account they control it and they buy whatever they want. Yeah. Wow the penny stock one that's nuts I hadn't caught that that's that's crazy yeah and it's very I mean it's really sad and it's really damaging we know some people that have lost their entire life savings they're retired they're on pension or whatever right and they lose everything. And when you lose four hundred dollars I mean you know this is kind of saying like it if you owe the bank four hundred dollars it's your problem if you owe the bank four million dollars it's the banks problem but if you lose your entire brokerage account it's unlikely depending on where you are and how much it was worth I mean it's much less likely that you'll be reimbursed. So those are really saddening but you know again like I said they're financially motivated and so at every turn they've sort of increased their ability to do this to scale it to steal greater amounts we believe that well we know that some of them are also involved in pig butchering type of scams you name it they're involved. I'm curious an innovation feels like such a weird word for this because of the kind of harms we're talking about but like I'm curious to understand where this innovation is coming from. I feel like here when we talk about people developing really complicated software the two stories are either like the wonder kind in a basement that hacks it together themselves or increasingly often like the person who gets ungodly gobs of like venture capital money. And then poachous talents and points it at a problem like a machine gun and I'm curious what does this look more like is it the individual author creating all of this is it more of the investor business model is it a crowdsour software project where wisdom of the crowd and people working together to come up with NFC relays and wallet layers like how where is that innovation coming from I think wisdom is wisdom of the crowd is probably the closest one. To the truth in at least just from what I observe we believe a lot of these developers are you know students or people who have recently graduated you know maybe in 20s 30s kind of age they have computer science degrees and backgrounds they are developers some of them we believe did you know had a real day job when they started working on this stuff and ultimately went on to kind of do this is a side hustle that became their main hustle. But in a lot of these channels there is you know that you'll see there are so many people offering their own services willing to work pitching ideas or hey does anybody have something that could work with this card or whatever and so there seems to be a collaborative nature to hey I want to get some money you want to get some money how can we figure out to do this. And then also at least in the the Chinese fraud ecosystem as we've seen it there has not really been much shame around copying other people's work so. If one fishing actor came with a new feature for instance in early twenty twenty five we saw this massive rotation in the U.S. and North America to toll road scams whereas before that everything was pretty much United States Postal Service package delivery scams but people had gotten so tired of it so fatigued I mean how many of these package messages did you get every day and you kind of knew it was a scam at that point so people weren't falling for it. So one of the actors decided to try up a playbook that had worked in another part of the world in Australia and New Zealand. These toll road scams had been very popular in Australia and New Zealand from twenty twenty three onwards and so they decided hey why don't we try these in the U.S. And they apparently had massive success and within just two or three days of one actor adding basically U.S. toll roads to their kit almost all the other major fishing as a service actors also supported toll roads and so I think part of that innovation is kind of like when one person figures out something that works they all that's the new baseline and then everybody's looking for the new thing that will improve that right. So they went from manually inputting card details to provision these wallets to automating it and we've seen some of the actors use like LLMs and AI to help a customer create like a very convincing brand impersonation so imagine if you have a particular brand you want to impersonate and the kit doesn't yet support it. There are features within the kit that are like AI enabled or AI powered that allow like a user who has no technical skill to say okay I want to impersonate this website and it'll go out and like make a capture scrape it all down, put things in the right format for like creating a skin for the fishing site and then that becomes a new template. So they've really been smart about how they kind of automate things about how they approach development and treat all of this like a real business. This is a maybe an unfair question or maybe more just a putting you on the spot but I am curious with everything that you know about this. If you could redesign any part of the financial ecosystem like how card issuers work and mobile wallets and telco messaging systems you could redesign some part of the financial system to try and shut down a big chunk of this fraud overnight like where would you intervene what's that bottleneck yeah this is always a tough one because everybody wants a silver bullet and there is no silver bullet there's a lot of things that need to come together. But I think one one thing that would have a massive impact in general is if we would move away from SMS for second factor because a it's clearly one of the easiest forms of MFA to bypass even if we don't talk about sim swapping but of course sim swapping does exist. SMS is unencrypted it's you know an aging protocol very old at this point it was really just a hack to begin with and one of the biggest sort of things that I see against SMS at least as a second factor is that a lot of times when the victim receives that that two factor code from their issuing authority. There's not a lot of context about what it's for it's just at best it's like hey this is chase and here's your code don't give it to anyone. And you know we at least with app based authorizations like let's say bank app based authorizations you will get some information that's like hey somebody is trying to add your card to an apple wallet device are you sure you want to allow this. And that becomes a lot harder for these red actors to overcome because even if the victim fell for the fish and they put all their information their card information in and the actor says okay now you need to open your banking app and approve. When they see what it's for I bet you a high percentage of people actually bail out at that point. I think there's something to be said for getting red or getting onto stronger forms of multi factor authentication either app based generator based is obviously a little better than text but still it's kind of weak because it's just a time based code and there's no context there you just have to provide your code for some thing. Like Fido and past keys and so on also really interesting we're not aware that these actors are able to bypass past keys because of sort of the nature of them of course I have some misgivings about some of the other things that past keys enable which is a lot of centralized lock into big players. The other thing I mean I know you asked for a single thing the other thing that is happening and we are getting much better at is we're so good at filtering spam messages from email and we have been for many many years now but we're terrible at it when it comes to text messaging. But that is changing right Android released an awesome feature related to like scam detection and possible scam detection for messages they also do things like call screening iOS now 26 apparently has a lot of anti scam or sort of anti spam message features as well as call screening unfortunately it's not available anywhere except the US as far as I'm aware maybe that's changed but we don't have access to it where I live in Europe. So if we can prevent people from seeing these messages and clicking on them and going to them that's a big impact as well. I'm curious where this goes next like they have truly embraced the move fast and break things philosophy they are iterating and coming up with new like templates and lures and ways of doing this what's that next adaptation where does this go say in 2026. I think it's yeah I think it's really going to be towards more account takeover type activity. Whether that's brokerages I'm not sure maybe the brokerages will will probably due to the amount of money involved probably pretty quickly kind of shut that down I would assume could be wrong about that but other forms of account takeover that allow them to monetize and do things useful. Whether that might be stealing like you know Amazon accounts or PayPal accounts or stripe accounts these kind of things that often have some sort of a payment. Like a payment channel associated with them or a card associated with them and allow you to buy things or transfer money. I think that's an area that so far we know that certain threat actors go after those type of things but the digital wallets was such a low hanging fruit that it just seemed like everything gravitated there for a long time because of all the advantages. But yeah I would think probably more targeted spear fishing or account takeover more kind of social engineering back stuff we know that they also have the the capability to bypass KYC controls there's a lot of stuff in the ecosystem about providing fake documents fake passports fake social security numbers ID cards. And we believe that they're also starting to leverage like a generative AI for videos to bypass these type of controls that when you open for instance a crypto account and you need to have your phones camera pointed at your face with a selfie and holding a passport next to it and move it in and out and all these kind of things. We believe they're also able to bypass those kind of controls so yeah it's hard to say exactly because I could have never predicted NFC relay or some of the other things that they've rotated to. But whatever it is I have a feeling it will be effective for sure to wrap up because you've been super generous with your time you spent years researching and unraveling and like trying to paint a picture of this what is it about this topic that kind of keeps you curious and engaged like what is the thread that you feel like you haven't pulled all the way on. I mean unfortunately it has been my feeling has been since I started looking into this that I wanted some closure before I was done right and I say unfortunately because I can see now that that is probably never going to happen. But I really initially thought like wow we've learned a lot about this we understand how it works if we just talk to the right people like we can make a difference and solve this problem. And the reality is while we've had I've had and a number of other people that are really close to this have had good impact here. At the end of the day like it's a never ending battle right this tale is as old as time you know that if you can convince somebody to give you your password or you can social engineer somebody into defeating the controls. Then no matter how sophisticated the controls get it never matters right like you can always just convince a human to defeat the controls for you. So in that sense I don't think this will ever really be resolved but my hope was that through our research and what we shared we could really like shut it down to a significant extent. So that's kind of what keeps me going and the other thing is as long as people have an interest in this and as long as people are losing money to this and want to talk about how it works. I'm happy to share that right because I think there needs to be more visibility more understanding of what's going on and when I talk to people about how it works. No matter if they're technical or not technical they always love to hear the story and learn how it works because we've all seen these messages and we all kind of I guess subconsciously wondered like what's that about or how are they even making money from this and when you show somebody that. And their eyes kind of light up and that light bulb goes off and they're bringing like oh that's how it works you know then they can go and tell their family and be like hey I understand how that works you need to be really careful about this or let's look at our op sec or let's look at how we address how we handle security because it is a very you know it's not only a personal responsibility it's also a societal and sort of government regulatory responsibility it's a responsibility of these companies but it's a responsibility of all of us. To sort of lift the level or the security level let's say so I guess that's really what keeps me going the hope that we can really make a difference in this kind of thing and the fact that people are interested in learning more about it and understanding more about it. Just as an aside I I think that people I think that we all have this feeling that we are on a daily basis even in something as innocuous as a text message you know the bad fat like Facebook add scam add that you try to avoid clicking on the link to the e-commerce site that seems seems right right like it seems like it's the real thing. We all have this feeling that like you are kind of in order to exist online you sort of have to consent to just being lied to with the potential for very real harm all of the time. There's this feeling of like when I wait into this world I'm waiting into a space where people are going to lie to me to try and steal from me all of the time and that feeling even if people aren't technical doesn't go and notice people it sort of builds up on you like a residue that there's someone always trying to tell me. So even for non technical folks I get why this would be a really compelling story. Yeah and you know to your point I mean it's unrealistic for anybody to have their guard at like you know the highest level at all times right so even if you don't fall for 99 out of 100 text messages the one time that you're busy or stressed or you've had something to drink or it's just early in the morning and you just woke up or you're tired. All it takes is once and that's what these actors are counting on it's a numbers game. We know from the numbers that they only one to three out of every one thousand victims that receives these messages actually goes through with clicking the link and losing their information and getting their card information provision. So that's less than one percent of everybody that receives it but it's clearly enough for them to make money at scale. Ford thank you so much for your time it was really good to get to talk to you I appreciate it. Yeah absolutely thanks so much for the time.
Podcast Summary
Key Points:
Mobile tap-to-pay (e.g., Apple Pay, Google Pay) uses tokenization and cryptographic codes for enhanced security, preventing exposure of real credit card numbers.
A sophisticated criminal enterprise, known as the "smishing triad" and centered on a service called "Lighthouse," has developed a method to bypass this security by using fake e-commerce sites to steal card details and instantly provision them into fraudsters' digital wallets.
This operation is highly industrialized, involving phishing-as-a-service software, automated wallet provisioning, and large-scale SMS spam, with estimates of over 115 million compromised payment cards and billions in fraud losses globally.
Summary:
The transcription discusses the security of mobile tap-to-pay systems and a large-scale criminal operation exploiting them. Tap-to-pay uses tokenization and unique cryptographic codes, making it more secure than traditional credit cards by never exposing the actual card number during transactions. However, a sophisticated organized crime group has innovated to compromise this system.
They operate a phishing-as-a-service platform called "Lighthouse," which provides tools for mass smishing (SMS phishing) campaigns. Victims are tricked into entering their credit card details on fake websites. The key innovation is an automated "wallet provisioning" process: the stolen card details are instantly displayed as a virtual card on a screen, which a fraudster's phone camera scans to add the card to a digital wallet like Apple Pay.
The scam simultaneously bypasses two-factor authentication by tricking the victim into providing the verification code. This enterprise-scale operation, described as "phishing for dummies," is highly automated and vertically integrated, leading to massive fraud estimated at over $1 billion and the compromise of tens of millions of payment cards worldwide.
FAQs
Tap-to-pay uses tokens and cryptographic codes instead of real credit card numbers, making transactions more secure. These tokens are device-specific and time-limited, preventing reuse if stolen.
A token is a 16-digit device account number that replaces your real credit card number during tap-to-pay. It is bound to your specific device and validated using secure hardware keys, so it's useless if stolen.
Wallet provisioning is the process of adding a credit card to a mobile wallet like Apple Pay or Google Wallet. Cybercriminals exploit it by using stolen card details to fraudulently add cards to their own devices, bypassing security measures.
Lighthouse is a phishing-as-a-service software that provides templates for fake e-commerce sites and automates smishing scams. It enables large-scale credit card theft and innovative fraud techniques like wallet provisioning.
They trick victims into entering their credit card details on fake sites, then use automated systems to add the card to a controlled device. Victims are prompted for a 2FA code, which is captured and used to authorize the fraudulent wallet addition.
The smishing triad uses industrialized, automated software like Lighthouse to target millions globally. Their tactics include geofencing, mobile-specific lures, and real-time wallet provisioning, leading to massive financial losses.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.