HomeSecurityNCR ransomware attack disrupts many POS systems

NCR ransomware attack disrupts many POS systems

NCR, a payment processor that offers point-of-sale systems to restaurants and retailers, digital banking and ATM services, is still recovering from a ransomware attack that began affecting systems on April 12.

See also: In 2023, Ukraine was the target of 60% of Russian phishing attacks

NCR ransomware

The cyberattack caused a data center outage affecting some operations at Aloha, a POS used by restaurants, and Counterpoint, which integrates front- and back-office management systems for retailers, NCR said in an updated incident report on Monday. The company first publicly disclosed it had been hit by a ransomware attack on April 15.

“At this time, our ongoing investigation also indicates that no customer systems or networks are involved ,” the company said in its incident report. “None of our ATMs, digital banking services, payments or other retail products are processed in this data center .”

On Tuesday, NCR said it aimed to fully restore its Command Center remote monitoring application within 24 hours, but did not provide further updates.

The company also said that efforts to restore Aloha Insight, NCR Back Office Cloud and Aloha Configuration Center are progressing.

See also: University sites using MediaWiki and TWiki hacked to spread Fortnite spams

"We previously shared our goal to bring all affected applications back online this week, and while that remains our goal, we hope to restore your services sooner," the company said in the incident report update.

The attack on NCR follows ransomware attacks on Yum Brands and Five Guys in January.

In-restaurant purchases are still being processed, but other features and business processes remain down, the company said. While restoration efforts are still ongoing, NCR said it has put in place local solutions to support impacted customer operations .

NCR ransomware attack disrupts many POS systems

"We are restoring the affected applications to a new secure environment. We will have further updates on the timeline for rebuilding this new environment and we aim to bring these applications back online this week," the company said.

NCR has not disclosed how many customers may be affected, and the company declined to answer questions. NCR claims that more than 100,000 restaurants currently use its platform. Some restaurants are reportedly unable to access back-office tools, process payroll or accept rewards points and gift cards.

See also: Experts warn: We don't know if we can protect ourselves from PIPEDREAM malware

“POS systems remain an attractive target for adversaries in ransomware attacks, given the business criticality of both customer payment data and the broader impact on business operations ,” Bugcrowd CEO Dave Gerry said via email.

NCR has not identified the threat actor behind the attack, but the BlackCat ransomware group – also known as AlphV – claimed responsibility on its website, according to independent security researcher Dominic Alvieri.

The ransomware group claims to have stolen credentials, which it uses as leverage to demand ransom, according to Tim Morris, Chief Security Advisor for the Americas region at Tanium.

Information source: cybersecuritydive.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS