Contributor

War on data escalates. Watch out for piggyback cards in POS terminals.

Opinion
Oct 13, 20083 mins
Point of seal terminal

First there was the drive by wireless hacks used against DSW and TJX. That was followed by the ingenious POS swap scheme at Stop and Shop ( Identity Theft Getting Physical  )  Remember? A team of three men would enter a convenience store; two would distract the sole employee while the third would swap out the credit card swipe machine, replacing it with one that had an extra chip in it that would record credit/debit card info and PINs.  They would return periodically to collect the machine and read the data stored on the chip. Now, EU law enforcement agencies are reporting that a huge crime ring has managed to infiltrate the manufacturing supply chain of point of sale  (POS) terminals.   Somewhere in China a daughter card is added to the machines.  The piggyback card selectively stores several credit cards each day then dials home to Pakistan to upload its data and receive fresh instructions.  The WSJ article does not make it totally clear but it sounds like it uses a cell phone network to call.   

“The account data have been used to make repeated bank withdrawals and Internet purchases, such as airline tickets, in several countries including the U.S. … Early estimates of the losses range of $50 million to $100 million, but the figure could grow, said the person close to British law enforcement.”

This represents a major new escalation on the part of cyber criminals. The WSJ makes the connection to terrorist networks based in Pakistan but that is circumstantial. Regardless of who these people are, the message to retailers is plain.  You are under attack by motivated, technically savvy cyber thieves. If you have value in the form of transactions, credit card info, account info, or even personally identifiable information, you are in grave risk of those assets being stolen. 

“In March, security officials at MasterCard Inc. saw a pattern of potential fraud in northern England. Meanwhile, a security guard at a U.K. grocery store noticed suspicious static on his cellphone and alerted authorities. Scotland Yard learned of the report and eventually connected it with the warning from MasterCard, according to the person close to British law enforcement.”

The only defense against these parasite ridden POS terminals is to weigh each one (the piggyback card weighs an additional four ounces).  Are you prepared to do the same?  Have you done an investigation into the source of the equipment you use in transacting business?  Perhaps a spot check of installed devices is called for.  There may be wireless monitoring solutions to detect the “phone home” activity.

Have you weighed your POS terminals lately? 

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author