PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Retail POS Hit By Fraud Again

By Raymond Pucci
October 3, 2017
in Analysts Coverage
0
2
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Merchant Shopping

Merchant Shopping

Another week, another payment security breach—make that two. This time, Whole Foods and Sonic have revealed their POS terminals have been compromised. The following article describes further details related to each case.

Two U.S. companies recently acknowledged high-profile point-of-sale (POS) breaches that affected an unknown number of customers.

On September 26, investigative reporter Brian Krebs announced that the fast food chain Sonic Drive-In, which has almost 3,600 locations across the U.S., had acknowledged a breach impacting an unidentified number of its locations’ PoS systems. The breach appeared to match a supply of approximately 5 million credit and debit card details that were being offered for sale at the cybercrime forum Joker’s Stash for $25 to $50 each.

In a statement provided to Krebs, Sonic said, “Our credit card processor informed us last week of unusual activity regarding credit cards used at Sonic. The security of our guests’ information is very important to Sonic. We are working to understand the nature and scope of this issue, as we know how important this is to our guests.”

“We immediately engaged third-party forensic experts and law enforcement when we heard from our processor,” the company added. “While law enforcement limits the information we can share, we will communicate additional information as we are able.”

Separately, on September 28, Whole Foods announced that it had learned of unauthorized access to payment card information used at taprooms and restaurants in some of its stores. Because those venues use a different PoS system than Whole Foods’ store checkout systems, the company said its checkout systems were not affected.

“When Whole Foods Market learned of this, the company launched an investigation, obtained the help of a leading cyber security forensics firm, contacted law enforcement, and is taking appropriate measures to address the issue,” the company said.

Since Whole Foods was recently acquired by Amazon.com, the statement noted that Amazon.com systems don’t connect to the affected PoS systems. “Transactions on Amazon.com have not been impacted,” Whole Foods said.

Unfortunately, these security breaches typically offer more questions than answers. The incidents are usually made public after a considerable amount of time. Often it’s a third party that reveals the breach. Then the merchants don’t give out much information and say that there is an ongoing investigation and that security experts have been brought in. Meanwhile, consumers are understandably frustrated. Lessons not learned: too many merchant POS terminals are not upgraded with the latest security defenses, plus many are unattended and easy prey for tampering.

Overview by Raymond Pucci, Associate Director, Research Services at Mercator Advisory Group

Read the full story here

2
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: Data BreachPoint of SaleRetail

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    Startups: Fintechs Data Streaming Technology in Banking, corporates Enriched Data vs Faster Payments

    Fighting Fraud in the Era of Faster Payments

    February 13, 2026
    cross-border payments

    Solving for Fraud in Cross-Border Payments Requires Better Counterparty Verification

    February 12, 2026
    agentic commerce

    Demystifying the Agentic Commerce Enigma

    February 11, 2026
    payment gateways

    How Payment Gateways for Businesses Can Help You Offer Your Customers More Options

    February 10, 2026
    Reserve Bank of India (RBI) Extends Mandate for Tokenization to June '22

    Late Payments? Governments Are Taking Action

    February 9, 2026
    ai phishing

    The Fraud Epidemic Is Testing the Limits of Cybersecurity

    February 6, 2026
    stablecoins b2b payments

    Stablecoins and the Future of B2B Payments: Faster, Cheaper, Better

    February 5, 2026
    Payment Facilitator

    The Payment Facilitator Model as a Growth Strategy for ISVs

    February 4, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result