First there was the drive by wireless hacks used against DSW and TJX. That was followed by the ingenious POS swap scheme at Stop and Shop ( Identity Theft Getting Physical ) Remember? A team of three men would enter a convenience store; two would distract the sole employee while the third would swap out the credit card swipe machine, replacing it with one that had an extra chip in it that would record credit/debit card info and PINs. They would return periodically to collect the machine and read the data stored on the chip. Now, EU law enforcement agencies are reporting that a huge crime ring has managed to infiltrate the manufacturing supply chain of point of sale (POS) terminals. Somewhere in China a daughter card is added to the machines. The piggyback card selectively stores several credit cards each day then dials home to Pakistan to upload its data and receive fresh instructions. The WSJ article does not make it totally clear but it sounds like it uses a cell phone network to call.
“The account data have been used to make repeated bank withdrawals and Internet purchases, such as airline tickets, in several countries including the U.S. … Early estimates of the losses range of $50 million to $100 million, but the figure could grow, said the person close to British law enforcement.”
This represents a major new escalation on the part of cyber criminals. The WSJ makes the connection to terrorist networks based in Pakistan but that is circumstantial. Regardless of who these people are, the message to retailers is plain. You are under attack by motivated, technically savvy cyber thieves. If you have value in the form of transactions, credit card info, account info, or even personally identifiable information, you are in grave risk of those assets being stolen.
“In March, security officials at MasterCard Inc. saw a pattern of potential fraud in northern England. Meanwhile, a security guard at a U.K. grocery store noticed suspicious static on his cellphone and alerted authorities. Scotland Yard learned of the report and eventually connected it with the warning from MasterCard, according to the person close to British law enforcement.”
The only defense against these parasite ridden POS terminals is to weigh each one (the piggyback card weighs an additional four ounces). Are you prepared to do the same? Have you done an investigation into the source of the equipment you use in transacting business? Perhaps a spot check of installed devices is called for. There may be wireless monitoring solutions to detect the “phone home” activity.
Have you weighed your POS terminals lately?




