Showing posts with label Retail POS. Show all posts
Showing posts with label Retail POS. Show all posts

Thursday, September 27, 2012

POS Hackers Sentenced for Multi-Million Dollar Payment Card Data Theft

Two Romanian nationals have plead guilty for participating in an international, multimillion-dollar scheme to remotely hack into and steal payment card data from hundreds of U.S. merchants’ computers, including a great number of Subway restaurants. Federal prosecutors noted that the conspiracies involved more than 146,000 compromised cards and more than $10 million in losses.
Iulian Dolan and Cezar Butu agreed to serve seven year and 21 month prison sentences respectively. Dolan, 28, of Craiova, Romania, pleaded guilty to one count of conspiracy to commit computer fraud and two counts of conspiracy to commit access device fraud, while Butu, 27, of Ploiesti, Romania, pleaded guilty to one count of conspiracy to commit access device fraud. A third co-conspirator, Adrian-Tiberiu Oprea, is currently awaiting trial in New Hampshire. The defendants admitted in their guilty pleas, that during a period roughly from in or about 2009-2011, they participated in Romanian-based conspiracies, to hack into hundreds of U.S.-based computers to steal credit, debit and payment account numbers and associated data. They then used the stolen payment card data to make unauthorized charges on, and/or transfers of funds from, those accounts (or alternatively to transfer the stolen payment card data to other co-conspirators who would do the same).       
The official judgment is a warning signal to all operators concerning POS security and describes how the hackers carried out the scheme. According to the official judgement, Dolan admitted that he, along with Oprea, remotely hacked into U.S. merchants’ point of sale (POS) where customers’ payment card data was electronically stored.
“Specifically, Dolan first remotely scanned the internet to identify U.S.-based vulnerable POS systems with certain remote desktop software applications (RDAs) installed on them. Using these RDAs, Dolan logged onto the targeted POS systems over the internet. These were typically password-protected, so Dolan would attempt to crack the passwords, where necessary, to gain administrative access. He would then remotely install software programs called ‘keystroke loggers’ (or ‘sniffers’) onto the POS systems. These programs would record, and then store, all of the data that was keyed into or swiped through the merchants’ POS systems, including customers’ payment card data.”
               
The co-conspirators hacked into several hundred U.S. merchants’ POS systems. It was reported that Dolan stole payment card data belonging to approximately 6,000 cardholders and was aware that Oprea was engaged in similar conduct. Dolan would periodically remotely hack back into the compromised merchants’ POS system to retrieve the card data that he would transfer to electronic “dump sites,” where the data would then be used to make unauthorized chargers and transfers or sold to other conspirators.
“The Subway case is a clear indication that privileged and administrative accounts are increasingly targeted and used by criminals to steal sensitive information,” says Adam Bosnian, vice president of products, strategy and sales at Cyber-Ark Software www.cyber-ark.com.  “In this case, the attackers were able to simply do an Internet search for remote desktop applications that were used by the restaurants, and through simple password cracking techniques, they were able to gain administrative access to the systems.  This enabled them to easily steal sensitive financial information from unsuspecting customers.”
Bosnian contends that often sensitive accounts are protected by passwords that are too simple or default passwords that are rarely changed. This case is a warning to operators utilizing POS systems to shore up their security by taking steps to make their accounts more difficult to breach and therefore less attractive to hackers.
“These privileged and administrative accounts act as a gateway to any organization’s most sensitive information, which is why they’ve emerged as the primary target for attackers,” Bosnian continues, “The reality is that anyone with an Internet connection can search for, identify and target  remote applications that businesses rely on – the problem facing the industry is that there is not sufficient security and protection around the entry points to these applications. Once inside, attackers have free reign on the network. If you examine the list of the recent, high-profile data breaches that have plagued organizations, including Global Payments, the U.S. Chamber of Commerce, the Utah healthcare breach, etc…, the common denominator is that the attackers focused on gaining access to the privileged or administrative accounts.” 

- Thanks to HT

Wednesday, November 25, 2009

Use the Right POS System for Your Business

A Point of Sale (POS) system is indispensable for any type of retail business. It is a combination of specialized hardware and computer hardware that allows staff members to enter customer purchases, manage inventory, take credit card payments, track expenses, generate reports, and much more. Whether you’re running a convenience store, restaurant, flower shop or specialty store, a POS system can help perform many different processes to maximize your efficiency.

Some of the chief benefits reported by businesses that use such systems include:

- More accurate and more detailed information - Greater productivity - The ability to share reliable information with product suppliers and other partners - The ability to operate on a leaner stock

Choosing a Point-of-Sale System Shopping around for a POS system for your business is no easy proposition. First, you must know your business very well and have a solid idea of how things run and what information will be most helpful to you. If that wasn’t enough of a challenge, comparing systems requires in depth knowledge of computers, networks, software features, and more. The market is flooded with POS systems of all complexity levels and price ranges. Knowing what to look for and where to start can be very difficult. Below are some guidelines to help you get started.

Identify Your POS Needs Identifying your point-of-sale needs can be as easy as finding out what your competitors (or other businesses similar to yours) are using or as difficult as performing an in-depth study of every transaction you process. It is a good idea to talk to your employees and your customers to get feedback on what kinds of features would help. For example, you could ask customers questions such as “do you ever shop with us online?” or “would you be interested in a frequent shopper program?” Also, keep in mind that even if there are software packages designed specifically for your type of business, they may vary wildly and you still need to research the features to determine what’ll work best for your business.

Establish a Budget A great way to narrow down your options is to establish a budget for your POS system expenditure. When doing so, remember that you will need to invest in a server (unless the system will work with your existing one) retail software, accounting software, terminals (how many will you need?) Talking to other business owners is a good way to get an idea of the range of what’s out there in terms of price.

Research the Market You may have initially taken a look at what’s available on the market in order to get an idea of what exists and in order to help you establish your budget. Now it is time to do more in-depth research and narrow down your choices. Once you find a system or two that seem to be the right fit for your company, you should research the providers. Make sure you are dealing with a reputable company known for providing outstanding service. Also, ask for and call references.

by Adriana Noton