How I opened a fake bank account and didn't go to prison

a66at 214 views 32 slides May 20, 2024
Slide 1
Slide 1 of 32
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32

About This Presentation

The presentation was given in 2022.
https://www.youtube.com/watch?v=zi0rpKe_DEk&t=23995s


Slide Content

How we opened a fake bank account And didn’t go to prison

Carding market overview

Let’s do that!

Now what? Let’s send them BTC and get our cards! But… You can go to prison You can loose your money

Instead of that…

How you would have assumed KYC works API for the Driving License and IDs checking Collaboration between GOVs (EU, USA, North Korea? )

How KYC actually works Liveness check (live capture from the phone, no photos) OCR data extraction “No visual tampering”, e.g. playing with channels Proof that the photos were not modified Black-lists Social media checks

Progressive KYC DOB, Address, no actual documents – < £100 One document (some ID) – < £1,000 Another document (proof of address) – >£1,000 Video instead of photo – any suspicions that the photos are not real Live interaction – scrutinize the documents, e.g. check the hologram

Simulation

How fraudsters bypass KYC 0. Have an agreement in place with the fintech you are trying to fool Photoshop Getting rid of tampering evidence Fake “plastic” that is suitable for video Fake holograms Stolen addresses, names, IDs – helpful but not mandatory

1. Photoshop

1. Photoshop

But don’t do that

2. Tampering evidence

3. Liveness check bypass – rooted phone

3. Liveness check bypass – virtual camera

4. Photo analysis – EXIF meta-tags

4. Photo analysis - strings

5. Social media, black-lists

Results

Results

It’s extremely easy to bypass KYC + Liveliness check + Present modified photos (face, name, details) + Visual tampering checks But don’t do that …

Why fraudsters open current accs ? Money laundering

Why fraudsters open current accs ?

Convenience vs security DOB, Address, no actual documents – < £100 One document – < £1,000 <- Should be Level 1 Another document – >£1,000 Video instead of photo Live interaction Endpoint anomaly detection (e.g. Biotech) Share data between KYC providers, GOVs, etc