Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Business > SECURITY SHOULD BE PHYSICAL AS WELL AS VIRTUAL FOR CARD PAYMENT MACHINES
    Business

    SECURITY SHOULD BE PHYSICAL AS WELL AS VIRTUAL FOR CARD PAYMENT MACHINES

    SECURITY SHOULD BE PHYSICAL AS WELL AS VIRTUAL FOR CARD PAYMENT MACHINES

    Published by Gbaf News

    Posted on March 27, 2014

    Featured image for article about Business

    Tailwind Solutions explores why a priority for retailers will be ensuring card readers are physically secure at Point of Sale in 2014

    The scandal at Target and Neiman Marcus stores over the 2013 Christmas period where up to 110,000,000 customers had personal and financial data stolen in Point of Sale skimming scams, has had long ranging consequences for the US card payment industry. EMV (Chip & PIN) adoption is now being accelerated and card issuers are changing the rules on how responsible a store is for data theft. From October 2015, instead of card issuers covering two thirds of any card related fraud, merchants will be liable for the full amount where an EMV-compliant card has been used in a payment terminal which is not EMV-compliant. However, card issuers will cover all fraud that results from the use of any card in any EMV-compliant terminal. But will EMV be a catch-all solution for Point of Sale card payment fraud? And would EMV have prevented the black Friday skimming at Target?

    Malware known as ‘Kaptoxa’, part of the BlackPOS malware family is the culprit in the Target data theft, scraping data from the Windows based payment system after it’s been decrypted to be checked in a process called ‘transaction verification’. BlackPOS malware first appeared in early 2013 but the most successful new variations appeared in November 2013 and were designed to hide their network traffic within the business day and to intercept credit card information after data is decrypted by ‘scraping’ data from process memory. Both the Cyrillic character set and the signature ‘Kaptoxa’ suggest a Russian origin for the malware[i].

    According to McAfee, the malware must be deployed onto a system which carries out external payment verification so although it is still not clear how the malware made it onto the EPOS systems of major retailers, it is likely to be through phishing or hacking rather than via the POS terminals or card reading machines. Because the data was stolen from the payment system, EMV would not have prevented the fraud, only better IT security which prevented the original malware infection could have achieved this.

    It’s therefore easy to conclude that if retailers plug the holes in their IT security, criminals will no longer be able to access customer card data and the problem will be solved. However it is more likely that as IT security becomes tighter, criminals will turn their attention to the card payment machine itself where there are multiple opportunities for data theft and where ‘real world’ security is often much more lax than in the cybersphere.

    The card reader itself is a hot target for criminals, who have a host of ways to steal customer data. This can be as simple as looking over the shoulder to see another shopper’s PIN (shoulder surfing), adding a chip to the card machine, installing malware onto the payment machine, to stealing and substituting the card reader itself.

    At Blackhat 2012 two researchers, in a talk called PinPadPwn[ii], demonstrated how a malicious smart (Chip & PIN) card can be used to place malware onto a POS payment device and display a fake messages to the retailer. The researchers also highlighted that hardware manipulation where a chip is physically added to the terminal or where a payment machine is stolen and replaced with a machine which has been adapted by criminals, are live issues for retailers around the world.

    So while IT network security is very important, protecting the hardware by ensuring no one can gain access to the back of the card payment machine or steal it should be just as high on a retailer’s priority list.

    Ideally, a card payment machine should be secured in place with a mount which prevents criminals from gaining access to the rear of the machine when in situ and from stealing and replacing the machine. A lockable mounting device where the card machine can only be removed with considerable mechanical force lowers risk, and when combined with network management tools which allow the devices on the network to be monitored and each machine recognised, risk is minimised as far as possible for physical interference.

    Determined criminals have been known to try colluding with store staff to get around these types of security measures. Merchants can prevent this by installing lockable bases for the card machines and limiting the number of staff who hold keys. Regular checks can help ensure that the correct number of machines are all present on the network and RFI technology can ensure they are the right machines. A hologrammed security sticker which shows clearly if the seal is intact can be useful to indicate the machine has not been tampered with and is still secure. Spare machines in storage should be securely locked away and accounted for, with care taken to ensure they are not accessible to casual staff or to the general public.

    Fraud protection is not the only benefit of mounting a card payment device. Card machine manufacturers use sensitive security systems which shut the machine down and wipe data if they detect activity that could indicate a ‘tamper’. This is a valuable way to protect customer information from genuine attacks, but a false tamper can be costly to the retailer, as the machine generally needs to be replaced. Mounting the machine reduces handling by customer and checkout staff, and the incidence of false tampers. Mounting also reduces the wear and tear on the machine and its cable as it’s passed backwards and forwards to the customer and extends the life of the machines.

    So, although criminals will always find new ways to target payments at POS, taking care with the physical security of your card payment technology by mounting your card reader as securely as possible, can be just as important to protecting your customer’s payment data as ensuring your IT network is secure. And the peace of mind you gain knowing you’re protecting your customers is just as important as the financial benefits gained from extending the lifespan of your payment technology.

    The writer, Ailsa Bates, is Marketing Director at Tailwind Solutions, which supplies secure and lockable mounting solutions for all kinds of card reader equipment. For more information visit: www.tailwind-solutions.co.uk,

    Follow Tailwind on LinkedIn: http://www.linkedin.com/company/tailwind-solutions-ltd?trk=top_nav_home or

    Follow on Twitter: https://twitter.com/TailwindSolns

    [i] See McAfee’s Threat Advisory for more information: “https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/24000/PD24927/en_US/McAfee_Labs_Threat_Advisory_EPOS_Data_Theft.pdf”>https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/24000/PD24927/en_US/McAfee_Labs_Threat_Advisory_EPOS_Data_Theft.pdf

    [ii] For more information see:

    http://www.securitytube.net/video/8833?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+SecurityTube+%28SecurityTube.Net%29

    Related Posts
    Five questions to ask before stepping into Employee Ownership
    Five questions to ask before stepping into Employee Ownership
    Cybersecurity as a Profit Engine: Turning Financial Services Security into Measurable Business Value
    Cybersecurity as a Profit Engine: Turning Financial Services Security into Measurable Business Value
    How Investability Helps Companies Navigate Transformational Times
    How Investability Helps Companies Navigate Transformational Times
    88% of UK and US organisations concerned about state-sponsored cyber attacks as national threat levels surge, IO research reveals
    88% of UK and US organisations concerned about state-sponsored cyber attacks as national threat levels surge, IO research reveals
    One in three SME leaders do not fully understand cash flow, despite 82% facing cash flow problems
    One in three SME leaders do not fully understand cash flow, despite 82% facing cash flow problems
    Inside the Company that Predicted the Remote Work Mega-Trend Before It Became Mainstream
    Inside the Company that Predicted the Remote Work Mega-Trend Before It Became Mainstream
    SEO Consultant Adrian Czarnoleski on How to Increase Business Value Before Exit
    SEO Consultant Adrian Czarnoleski on How to Increase Business Value Before Exit
    No SOC 2, No Deal: Why You’re Already Losing Clients - and What You Can Do About It
    No SOC 2, No Deal: Why You’re Already Losing Clients - and What You Can Do About It
    Jose Tolosa Guides Organizations Forward with Clarity, Purpose, and Integrity
    Jose Tolosa Guides Organizations Forward with Clarity, Purpose, and Integrity
    Reducing Freight Costs to Drive Global Trade Expansion
    Reducing Freight Costs to Drive Global Trade Expansion
    The Psychology of Music in the Modern Workplace
    The Psychology of Music in the Modern Workplace
    Revealed: Low-Cost/No-Cost Marketing Hacks For Results Oriented Businesses
    Revealed: Low-Cost/No-Cost Marketing Hacks For Results Oriented Businesses

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Business PostAUTOMATED ADVICE FOR FORWARD THINKING ADVISERS
    Next Business PostHOW THE BIG BUSINESS USES THE EMOTIONAL POWER OF LOGOS

    More from Business

    Explore more articles in the Business category

    Finance teams still stuck in spreadsheets as manual processes stall digital transformation

    Finance teams still stuck in spreadsheets as manual processes stall digital transformation

    The Future of Remote & Hybrid Leadership: Leading With Data-Driven Foresight

    The Future of Remote & Hybrid Leadership: Leading With Data-Driven Foresight

    2025-2030: The Next Technological Innovations for Business

    2025-2030: The Next Technological Innovations for Business

    The CFO’s New Playbook: 5 Ways AI Is Redefining Finance with Insights from Rishi Oberoi

    The CFO’s New Playbook: 5 Ways AI Is Redefining Finance with Insights from Rishi Oberoi

    Revolutionizing Payments: Secure, Scalable, Sovereign

    Revolutionizing Payments: Secure, Scalable, Sovereign

    Why Trademark Abuse in Paid Search Is a Growing Risk for Financial Institutions

    Why Trademark Abuse in Paid Search Is a Growing Risk for Financial Institutions

    E-commerce Customer Service: Tips

    E-commerce Customer Service: Tips

    When to Automate Your Warehouse: The Tipping Point for Operations Growth

    When to Automate Your Warehouse: The Tipping Point for Operations Growth

    Hurt at Work? 5 Financial Facts You Need to Know

    Hurt at Work? 5 Financial Facts You Need to Know

    Against the Odds: Resilience in Consumer Subsectors Offers Prime Opportunities for Investors

    Against the Odds: Resilience in Consumer Subsectors Offers Prime Opportunities for Investors

    Empower Your Workforce With Financial Wellness This Labor Day

    Empower Your Workforce With Financial Wellness This Labor Day

    Build a brand that stands out with five simple strategies, from defining your UVP to using storytelling and building loyalty. Find out more.

    Build a brand that stands out with five simple strategies, from defining your UVP to using storytelling and building loyalty. Find out more.

    View All Business Posts