Company News • 08.04.2014

Mobile Point of Sale devices could leave millions worldwide open to attack

Mobile Point of Sale (MPOS) devices can be easily hacked, leaving banks, retailers and millions of customers exposed to serious fraud around the world, global information security firm MWR InfoSecurity has revealed at the SyScan security conference in Singapore today.

Security researchers from MWR Labs, the research arm of the company, who in 2012 revealed critical vulnerabilities in Chip-and-Pin devices, demonstrated at the conference that it is possible to compromise MPOS terminals with multiple attacking techniques using micro USBs, Bluetooth and a malicious programmable smart card.

Jon, Head of research at MWR InfoSecurity, said: “What we have found reveals that criminals can compromise the MPOS payment terminal and get full control over it. This would allow an attacker to gather PIN and credit card data, and event change the software on the device so that it accepts illegitimate payments.”

He added: “This shows that card holders paying at MPOS terminals worldwide are potentially at risk. Banks and retailers should also be wary when implementing this technology as it could leave them open to serious fraud.”

MWR’s researchers demonstrated how an attacker could gain control over the MPOS terminal. This allowed them to display ‘try again’ messages, switch the device into insecure mode, capture the PIN code when entered and even enable it to accept stolen credit cards. They were even able to use the device to play a simplified version of the popular game Flappy Bird.

Nils, a security researcher at MWR, said: “MPOS is a promising technology with a growing market uptake, well suited for use in modern payment systems, but current implementations are not well designed from a security perspective. It is critical to get security right early as there is a huge potential for fraud around the world.”

He added: "Lessons that have been learned from desktop computers and servers are yet to be applied to embedded systems."

The team discovered the issues as part of its ongoing research programme into secure payment technologies. Companies use MWR to understand how they may be vulnerable to fraud and attack by criminals using advance and sophisticated attacks.

The company has notified the vendors involved and has assisted with the relevant information needed to address the identified issues. They are unable to provide any specific details on the vulnerabilities found as the devices concerned are currently being used at thousands of retail outlets in the UK and around the world.

Source: MWR InfoSecurity

related articles:

popular articles:

Thumbnail-Photo: SES-imagotag becomes VusionGroup
29.01.2024   #software applications #artificial intelligence

SES-imagotag becomes VusionGroup

A new identity highlighting the broader portfolio of innovative solutions
developed by the Group to solve the major challenges of physical commerce

SES-imagotag (Euronext: SESL, FR0010282822), the global leader in digital solutions for physical commerce, today announced that it has changed its name to VusionGroup. This new name embodies the various product lines and solutions that have enhanced ...

Thumbnail-Photo: Tesco to introduce new scan-free technology on self-service tills at...
03.01.2024   #brick and mortar retail #Tech in Retail

Tesco to introduce new scan-free technology on self-service tills at GetGo store

Seamless Shopping Revolution: Tesco Tests Scan-Free Technology in London

Tesco is trialling an exciting new technology innovation that means customers don’t need to scan their items ...

Thumbnail-Photo: The global state of autonomous stores
18.12.2023   #Tech in Retail #self-checkout systems

The global state of autonomous stores

The stores are located in various retail segments such as food retail, fashion, electronics, convenience stores and fast food.

In a highly competitive global retail landscape, autonomous stores are an emerging force that addresses changing consumer behaviors, reduces operational costs, improves profitability, and powers revenue growth strategies. Advancements in autonomous ...

Thumbnail-Photo: ‘Problem-solving mission’ with updated Modern Store Framework...
16.02.2024   #Tech in Retail #personnel management

‘Problem-solving mission’ with updated Modern Store Framework

Zebra Technologies will be looking to address challenges with expertise and new solutions at EuroCIS

Zebra Technologies Corporation (NASDAQ: ZBRA), a leading digital solution provider enabling businesses to intelligently connect data, assets, and people, today announced it’s taking the newly enhanced Modern Store framework on a ‘problem ...

Thumbnail-Photo: EuroCIS 2024 - technology special
11.12.2023   #online trading #e-commerce

EuroCIS 2024 - technology special

The latest technology solutions and trends for you and the retail sector

At EuroCIS 2022 from February 27 to 29, 2024, the Leading Trade Fair for Retail Technology, we will be looking at all the important and current topics relating to technology in retail: AI and Machine Learning, Payment, Connected Retail, Seamless Store and Smart Energy Management and many more.

Thumbnail-Photo: EuroCIS Germany next stop for ITL’s cash handling and age verification...
13.02.2024   #Tech in Retail #artificial intelligence

EuroCIS Germany next stop for ITL’s cash handling and age verification solutions

Innovative Technology Ltd (ITL) will be joining retail suppliers and industry professionals at ‘EuroShop 2024 – the leading trade fair for retail technology’ which takes place in Düsseldorf, Germany from ...

Thumbnail-Photo: MPREIS Transforms Operations with Zebra Workcloud Task Management™...
06.11.2023   #customer experience #software developement

MPREIS Transforms Operations with Zebra Workcloud Task Management™ Software Solution

Austrian food retailer to streamline communication in around 300 stores to improve staff engagement, inventory optimisation, and customer satisfaction

MPREIS has around 300 Austrian stores in regions across Tyrol...

Thumbnail-Photo: First of its kind accessible checkout unveild by Woolworths, creating...
03.01.2024   #Tech in Retail #cashpoints

First of its kind accessible checkout unveild by Woolworths, creating new employment opportunities

Breaking Barriers in Retail: Woolworths' New Checkout Design for Wheelchair Users

In what is believed to be a world first, Woolworths has unveiled an accessible checkout, designed specifically for team members living with a physical disability, including people who use wheelchairs and other mobility aids such as walkers.The first ...

Thumbnail-Photo: Out of Stock in Retail and innovative solutions to avoid them...
07.11.2023   #brick and mortar retail #customer satisfaction

Out of Stock in Retail and innovative solutions to avoid them

Due to various events, the availability of goods in retail will be increasingly restricted from 2022, with the result that customers cannot find in food retail the products they wish to buy, because those products are sold out, are temporarily ...

Thumbnail-Photo: Wayfair Announces Decorify App for Apple Vision Pro...
15.02.2024   #Tech in Retail #virtual reality

Wayfair Announces Decorify App for Apple Vision Pro

Wayfair's virtual room styler and 3D imaging tools enable Apple Vision Pro users to reimagine their living spaces and experience the future of shopping in their home

With the Wayfair Decorify app on Apple Vision Pro, users have a variety of options to see their spaces redesigned. They can upload a photo of their space ...

Supplier

Captana GmbH
Captana GmbH
Bundesstraße 16
77955 Ettenheim
SALTO Systems GmbH
SALTO Systems GmbH
Schwelmer Str. 245
42389 Wuppertal
Zebra Technologies Germany GmbH
Zebra Technologies Germany GmbH
Ernst-Dietrich-Platz 2
40882 Ratingen
Innovative Technology Ltd.
Innovative Technology Ltd.
Innovative Business Park
OL1 4EQ Oldham
VusionGroup SA
VusionGroup SA
55 place Nelson Mandela
90000 Nanterre