Popular now
Freemans defies high street slump with sixth year of festive growth

Freemans defies high street slump with sixth year of festive growth

Waitrose secures Surrey site with shopping centre acquisition

Waitrose secures Surrey site with shopping centre acquisition

WHSmith opens three new sites at Manchester and Liverpool airports

WHSmith opens three new sites at Manchester and Liverpool airports

The bull’s eye for cyber criminals: PoS Systems

The bull’s eye for cyber criminals: PoS Systems

In this episode we speak to Matt Dalton, consumer sector leader at Forvis Mazars. Matt discussed the biggest challenges facing the retail sector, from cost pressures and wage increases to polarised property markets and geopolitical shocks, and the ways in which retailers can best navigate these. We also explore how short-term cost-cutting could undermine long-term resilience, and how retailers can best remain agile and adaptable in unforecastable times.

Register to get 5 free articles

Reveal the article below by registering for our email newsletter.

No spam Unsubscribe anytime

Want unlimited access? View Plans

Already have an account? Sign in

Point of Sale (Pos) systems that take payments for goods and services for the hospitality and retail industries really serve as the point-of-strike for cyber criminals stealing credit card information.

Applebee’s, a popular restaurant chain, is the latest to find malware on their PoS systems that infected more than 160 restaurants across the United States. The malware was designed to secure names, credit or debit card numbers, expiration dates, and card verification codes.

Applebee’s is not alone in this predicament. Other companies have suffered the same indignities through their PoS systems, and the trend will continue.

Point-of-Strike

Cybercriminals have scoured the computer systems for the hospitality and retail industries and found an easy way into the store network through the PoS workstation. This part of the system doesn’t check when someone has approved access to perform critical functions, as discovered by researchers at ERPScan. The red cloak is raised, and cybercriminals just need to connect a $25 (£17) Raspberry Pi to the network to upload malicious code to come charging into the network.

Malicious software like PoSeidon, Alina, vSkimmer, Dexter, and FYSNA are uploaded to gather credit card information and send it back to the cyber criminal’s server. Another kind of point-of-sale malware discovered by researchers at Forcepoint hides inside DNS requests to steal credit card data. This UDPoS hides in a DNS request to steal credit card data, which makes it a little more stealth and harder to detect.

The other opening for cyber criminals is third-party suppliers that subcontract with restaurants and retailers. Those organizations, in turn, hire other companies creating a long chain of providers that handle sensitive data. It is in this chain that credit card information is potentially exposed.

Corralling ‘the bull’

The only way to combat this barrage of cyberattacks is to continuously monitor PoS devices and install patches regularly. In the case of the Forever 21 PoS breach, for example, the fraudsters took advantage of some PoS devices that were not updated with the latest security.

Neutralizing the credit card information after a breach is another way to combat fraudulent transactions. Restaurants, retailers, and other companies offering services in the card-not-present (CNP) channel need to identify customers by means that don’t rely on the – potentially stolen – static data. By analysing the user’s online behaviour through hundreds of other identifiers that hackers can’t imitate or steal, the stolen data is not useful anymore.

Multi-layered security solutions that include passive biometrics and behavioural analytics allow vendors to protect customers whose data was stolen while avoiding fraud from happening in their environment.


NuData Security is an award-winning passive biometrics and behavioral analytics company. Our flagship product, NuDetect, helps companies identify users based on their online interactions – behavior that can’t be mimicked or replicated by a third party.

Previous Post
Dominic Chappell banned from company directorship for 15 years

Dominic Chappell banned from company directorship for 15 years

Next Post
Online retail orders on the up

Online retail orders on the up

Secret Link