HomeinetAttacks on POS (Point of Sales) systems

Attacks on POS (Point of Sales) systems

Theft of credit and debit card data is one of the oldest forms of cybercrime and it still exists today. Let's look at attacks on POS (Point of Sales) systems.

POS

Organized cyber‑criminal groups conduct sophisticated operations aimed at stealing large volumes of data, which they later sell on illegal markets. The criminals can use the data they steal from a card’s magnetic strip to create clones. This is an attractively profitable business, with the cards fetching sale prices that reach up to $100 each in the United States.

Intruders can follow various methods to steal this data. One option is to gain access to a database where the card data is stored. However, another option is to target the point at which the retail merchant first obtains the card data: the Point of Sale (POS) system, i.e., the point of sale.

The modern POS systems are specially configured computers that have sales software installed and are equipped with a card reading mechanism. Card data can be stolen by installing a device on the card reading mechanism, which can read the data from the card's magnetic strip. This process is known as “skimming”. Since this process requires additional hardware equipment and personal access to the card reading mechanism, it is difficult to carry out such a theft on a large scale.

These practical difficulties led to the development of malicious software that has the ability to copy card data as soon as the card reading mechanism reads it. The first attacks of this type were observed in 2005 in a series of attacks created by Mr. Albert Gonzalez. These attacks resulted in the theft of over 170 million card numbers. Since then, an entire industry has developed around attacks on POS systems with tools that are easily available on illegal markets.

Despite the improvements in card security technologies and the requirements of the PCI DSS (Payment Card Industry Data Security Standard), gaps still exist in the security of POS systems. This fact, combined with broader weaknesses in the IT infrastructure security of companies, means that retail points of sale are exposed to cybercriminal groups that are becoming increasingly inventive and organized.

Download the full report (PDF)

From Symantec newsletter

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS