Your credit card can be hacked in just six seconds!

December 2, 2016

London, Dec 2: It may take as little as six seconds for hackers to guess your credit or debit card number, expiry date and security code, say scientists who were able to circumvent all security features meant to protect online payments from fraud.

card
Exposing the flaws in the VISA payment system, researchers from Newcastle University in the UK, found neither the network nor the banks were able to detect attackers making multiple, invalid attempts to get payment card data.

By automatically and systematically generating different variations of the cards security data and firing it at multiple websites, within seconds hackers are able to get a 'hit' and verify all the necessary security data.

Investigators believe this guessing attack method is likely to have been used in the recent Tesco cyberattack which the Newcastle team describe as "frighteningly easy if you have a laptop and an internet connection."

"This sort of attack exploits two weaknesses that on their own are not too severe but when used together, present a serious risk to the whole payment system," said Mohammed Ali, a PhD student at Newcastle University.

"Firstly, the current online payment system does not detect multiple invalid payment requests from different websites," said Ali.

"This allows unlimited guesses on each card data field, using up to the allowed number of attempts - typically 10 or 20 guesses - on each website," he said.

"Secondly, different websites ask for different variations in the card data fields to validate an online purchase. This means it's quite easy to build up the information and piece it together like a jigsaw," Ali said.

"The unlimited guesses, when combined with the variations in the payment data fields make it frighteningly easy for attackers to generate all the card details one field at a time," he said.

"Each generated card field can be used in succession to generate the next field and so on," Ali said.

"If the hits are spread across enough websites then a positive response to each question can be received within two seconds - just like any online payment," he said.

"So even starting with no details at all other than the first six digits - which tell you the bank and card type and so are the same for every card from a single provider - a hacker can obtain the three essential pieces of information to make an online purchase within as little as six seconds," he said.

To obtain card details, the attack uses online payment websites to guess the data and the reply to the transaction will confirm whether or not the guess was right.

Since the current online system does not detect multiple invalid payment requests on the same card from different websites, unlimited guesses can be made by distributing the guesses over many websites.

However, the team found it was only the VISA network that was vulnerable. The research was published in the academic journal IEEE Security and Privacy.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 19,2025

Mangaluru: Public transport in Mangaluru is set for a state-led transformation as the government moves to deploy 100 new electric govt buses to replace unreliable private services. The initiative aims to provide a dependable alternative to private operators who have been frequently "cutting trips," leaving thousands of commuters stranded.

The announcement was made by Deputy Commissioner and MCC Administrator Darshan HV during a public phone-in session. The move specifically targets routes where private bus service has become erratic, ensuring that citizens no longer have to rely on a fluctuating private sector for their daily commute.

Restoring the Govt Presence

The transport crisis was brought to the forefront by Ramayya, a resident of Bajal, who highlighted a growing trend of private buses skipping morning and night trips. With the previous KSRTC (govt) services discontinued, residents have been left without a fallback option.

To fix this, the DC confirmed that the PM-eBus Sewa Scheme will bring 100 government-owned electric buses to the city:

•    Phased Deployment: The first 50 of the new 100 government buses are scheduled to arrive by March 2026.

•    State Infrastructure: Two new government depots, including one at Mudipu, are being prepared for operations.

•    Recruitment: The state has already begun training a new batch of government bus drivers to ensure the fleet is operational the moment it arrives.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 15,2025

Mangaluru, Dec 15: Air India Express has announced that it will resume direct flight services between Mangaluru and Muscat from March 2026, restoring an important international air link for passengers from the coastal region.

Airport authorities said the service will operate twice a week—on Sundays and Tuesdays—from March 1. The initial flights are scheduled on March 3, 8 and 10, followed by March 15 and 17, with the same operating pattern to continue thereafter. The flight duration is approximately three hours and 25 minutes.

The Mangaluru–Muscat route was earlier operated under the 2025 summer schedule, with services beginning on July 14. At that time, Air India Express had operated four flights a week before suspending the service.

Officials said the summer schedule will come into effect from March 29, after which changes in flight timings and departure schedules from Mangaluru are expected. Passengers have been advised to check the latest schedules while planning their travel.

The resumption of direct flights to Muscat is expected to significantly benefit expatriates, business travellers and others, further strengthening Mangaluru’s air connectivity with the Gulf region.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 15,2025

Mangaluru police have arrested a 27-year-old NRI on his return from Saudi Arabia in connection with an Instagram post allegedly containing derogatory and provocative remarks about the Hindu religion, officials said on Monday.

The accused, Abdul Khader Nehad, a resident of Ulaibettu in Mangaluru, was working in Saudi Arabia when the post was uploaded, police said.

A suo motu case was registered at the Bajpe police station on October 11 after an allegedly offensive post circulated from the Instagram account ‘team_sdpi_2025’. Police said the content was flagged for being provocative and derogatory in nature.

During the investigation, technical analysis traced the Instagram post to Nehad, who was residing abroad at the time, a senior police officer said. Based on these findings, a Look Out Circular (LOC) was issued against him.

On December 14, Nehad arrived from Saudi Arabia at Calicut International Airport in Kerala, where he was taken into custody on arrival. Police said further investigation is underway.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.