How I opened a fake bank account and didn't go to prison
a66at
214 views
32 slides
May 20, 2024
Slide 1 of 32
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
About This Presentation
The presentation was given in 2022.
https://www.youtube.com/watch?v=zi0rpKe_DEk&t=23995s
Size: 12.09 MB
Language: en
Added: May 20, 2024
Slides: 32 pages
Slide Content
How we opened a fake bank account And didn’t go to prison
Carding market overview
Let’s do that!
Now what? Let’s send them BTC and get our cards! But… You can go to prison You can loose your money
Instead of that…
How you would have assumed KYC works API for the Driving License and IDs checking Collaboration between GOVs (EU, USA, North Korea? )
How KYC actually works Liveness check (live capture from the phone, no photos) OCR data extraction “No visual tampering”, e.g. playing with channels Proof that the photos were not modified Black-lists Social media checks
Progressive KYC DOB, Address, no actual documents – < £100 One document (some ID) – < £1,000 Another document (proof of address) – >£1,000 Video instead of photo – any suspicions that the photos are not real Live interaction – scrutinize the documents, e.g. check the hologram
Simulation
How fraudsters bypass KYC 0. Have an agreement in place with the fintech you are trying to fool Photoshop Getting rid of tampering evidence Fake “plastic” that is suitable for video Fake holograms Stolen addresses, names, IDs – helpful but not mandatory
1. Photoshop
1. Photoshop
But don’t do that
2. Tampering evidence
3. Liveness check bypass – rooted phone
3. Liveness check bypass – virtual camera
4. Photo analysis – EXIF meta-tags
4. Photo analysis - strings
5. Social media, black-lists
Results
Results
It’s extremely easy to bypass KYC + Liveliness check + Present modified photos (face, name, details) + Visual tampering checks But don’t do that …
Why fraudsters open current accs ? Money laundering
Why fraudsters open current accs ?
Convenience vs security DOB, Address, no actual documents – < £100 One document – < £1,000 <- Should be Level 1 Another document – >£1,000 Video instead of photo Live interaction Endpoint anomaly detection (e.g. Biotech) Share data between KYC providers, GOVs, etc