PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Retail Systems Under Attack

By Raymond Pucci
March 30, 2016
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

Chatbot.

Just when we thought retail POS systems had become more secure from cybercriminals, we are learning that may not be the case. Cyber security software developer, FireEye, is reporting that many types of malware are still being found on merchants’ payments processing systems.

Cybercriminals are redoubling efforts to steal payment card details from retailers before new defenses are put in place, according to FireEye. More than a dozen types of malware were found last year that target point-of-sale systems, the electronic cash registers the process payments at many retailers.

Over the last few years, hackers have successfully breached the systems, targeting weaknesses or software vulnerabilities in order to extract card details to sell on the black market.

Major retailers affected by card breaches in the last few years, including Target, have upgraded their systems. But the cost and long delays in getting new systems certified have delayed the transition, leaving a windows for cybercriminals.

Nart Villeneuve, a senior threat intelligence researcher with FireEye, wrote on Monday that more than a dozen malware families that target POS systems were found last year.

“Criminals appear to be racing to infected POS systems in the United States before U.S. retailers complete this transition,” Villeneuve wrote.

In response, card issuers and banks have improved their ability to identify and block potentially fraudulent transactions. But the potential windfall has criminals working overtime.

Villeneuve described a new type of POS malware called Treasurehunt, which steals payment card data from a computer’s memory.

“In a typical scenario, Treasurehunt would be implanted on a POS system through the use of previously stolen credentials or through brute forcing common passwords that allow access to poorly secured POS systems,” he wrote.

Both the EMV transition and card-not-present issues may have distracted us from the payments security risks still present in merchants’ point-of-sale systems. Those risks have not gone away despite more sophisticated cyber security measures. Not surprisingly, the malware has become smarter too, and fraudsters will typically gravitate to mass retailers’ credit card databases—because that’s where the money is.

Overview by Raymond Pucci, Associate Director, Research Service at Mercator Advisory Group

Read the full story here

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    fraud as a service

    Keeping Up with the Most Dangerous Fraud Trends of 2026

    December 8, 2025
    open banking

    Open Banking Has Begun to Intrude on Banks’ Customer Relationships

    December 5, 2025
    conversational payments

    Conversational Payments: The Next Big Shift in Financial Services  

    December 4, 2025
    embedded finance

    Inside the Embedded Finance Shift Transforming SMB Software

    December 3, 2025
    metal cards

    Metal Card Magnitude: How a Premium Touch Can Enthrall High-Value Customers

    December 2, 2025
    digital gift cards

    How Nonprofits Can Leverage Digital Gift Cards to Help Those in Need

    December 1, 2025
    stored-value prepaid

    How Stored-Value Accounts Are the Next Iteration of Prepaid Payments

    November 26, 2025
    google crypto wallet, crypto regulation

    Crypto Heads Into 2026 Awaiting Its ‘Rocketship Point’

    November 25, 2025

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result