HomeSecurityVISA: POS malware attacks on US fuel companies

VISA: POS malware attacks on US fuel companies

Payment processing company VISA reported that North American businesses are facing attacks from hackers. Specifically, the vulnerable businesses operate gas stations and pumps. The hackers aim to deploy POS malware on the companies' networks.POS

According to VISA , at least five such incidents have been discovered and investigated recently

The hackers' main goal was to gain access to networks fuel distributorby installing POS malware.

POS malware works like this: it searches a computer's RAM for unencrypted payment card data. It then collects the data and uploads it to a remote server.

The VISA Payment Disruption (PFD) team said that hacking groups found a weak spot in the operation of gas stations and businesses that manage gas pumps, and exploited it.

While some POS terminals support chip-and-PIN transactions, most “card readers” installed at gas pump businesses do not.

These devices still operate on older technology, which only reads payment data from the cards' magnetic stripe.

VISA: POS malware attacks on US fuel companies

Data from these outdated devices is sent to the gas station's main network unencrypted. Hackers knew this and so breached the businesses' networks.

In November, VISA disclosed breaches at two businesses and in December another three. These revelations show that cybercriminal groups have found a new target and method of attack.

According to VISA, the attacks on fuel businesses began in the summer. Two of the five attacks were linked to a known hacking group, FIN8.

VISA said there are some easy ways customersfuel distributors could protect encrypting card data and 2) using a POS terminal that supports chip-and-PIN transactions.

The second security practice can significantly reduce the chances of such attacks.

By October 2020, all these businesses are required to change their POS terminals to support such transactions. However, until then, they are still vulnerable to attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS