Company News • 08.04.2014

Mobile Point of Sale devices could leave millions worldwide open to attack

Mobile Point of Sale (MPOS) devices can be easily hacked, leaving banks, retailers and millions of customers exposed to serious fraud around the world, global information security firm MWR InfoSecurity has revealed at the SyScan security conference in Singapore today.

Security researchers from MWR Labs, the research arm of the company, who in 2012 revealed critical vulnerabilities in Chip-and-Pin devices, demonstrated at the conference that it is possible to compromise MPOS terminals with multiple attacking techniques using micro USBs, Bluetooth and a malicious programmable smart card.

Jon, Head of research at MWR InfoSecurity, said: “What we have found reveals that criminals can compromise the MPOS payment terminal and get full control over it. This would allow an attacker to gather PIN and credit card data, and event change the software on the device so that it accepts illegitimate payments.”

He added: “This shows that card holders paying at MPOS terminals worldwide are potentially at risk. Banks and retailers should also be wary when implementing this technology as it could leave them open to serious fraud.”

MWR’s researchers demonstrated how an attacker could gain control over the MPOS terminal. This allowed them to display ‘try again’ messages, switch the device into insecure mode, capture the PIN code when entered and even enable it to accept stolen credit cards. They were even able to use the device to play a simplified version of the popular game Flappy Bird.

Nils, a security researcher at MWR, said: “MPOS is a promising technology with a growing market uptake, well suited for use in modern payment systems, but current implementations are not well designed from a security perspective. It is critical to get security right early as there is a huge potential for fraud around the world.”

He added: "Lessons that have been learned from desktop computers and servers are yet to be applied to embedded systems."

The team discovered the issues as part of its ongoing research programme into secure payment technologies. Companies use MWR to understand how they may be vulnerable to fraud and attack by criminals using advance and sophisticated attacks.

The company has notified the vendors involved and has assisted with the relevant information needed to address the identified issues. They are unable to provide any specific details on the vulnerabilities found as the devices concerned are currently being used at thousands of retail outlets in the UK and around the world.

Source: MWR InfoSecurity

related articles:

popular articles:

Thumbnail-Photo: Time saving made easy
18.07.2024   #brick and mortar retail #software applications

Time saving made easy

Use of technology in retail: focus on increasing efficiency and customer satisfaction

Task management software is one of the retail solutions designed to help shops save time and ...

Thumbnail-Photo: Transform Customer Interactions with apg® Customizable Kiosk Floor Stand...
06.08.2024   #customer experience #kiosk applications

Transform Customer Interactions with apg® Customizable Kiosk Floor Stand

The leading provider of point-of-sale cash management and retail solutions, proudly announces the launch of its new Kiosk Floor Stand.

This innovative stand is designed to revolutionize customer service in various business environments through its high adaptability and user-focused design.The apg® Kiosk Floor Stand is unique in its ability to meet the diverse needs of different ...

Thumbnail-Photo: Hanshow Awarded FY24 China Top ISV Partner by Microsoft for Innovative...
04.09.2024   #artificial intelligence #cloud computing

Hanshow Awarded FY24 China Top ISV Partner by Microsoft for Innovative Retail Solutions

Hanshow, a leading provider of retail digital store solutions, has been awarded the "FY24 China Top ISV Partner" by Microsoft. The award recognizes Hanshow's innovative technologies and deep cooperation with Microsoft in the field of ...

Thumbnail-Photo: Zebra: Using transparency to combat losses and shrinkage...
24.05.2024   #Tech in Retail #personnel management

Zebra: Using transparency to combat losses and shrinkage

Companies in the retail sector like Lowes Food, Belk’s and Vera Bradley are gearing themselves up for the future with cost optimisation strategies.

Loss prevention is playing an increasingly important role in reducing inventory discrepancies.Inventory is a major challenge for companies in the retail sector: 82% of retailers in Zebra's latest 16th Annual Global Shopper Study say that ...

Thumbnail-Photo: Introducing the Design XS Keypad Wall Reader Series...
23.07.2024   #access control #authentication

Introducing the Design XS Keypad Wall Reader Series

A New Level of Security and Convenience for Access Control

Leading global access solutions provider Salto Systems, part of SALTO WECOSYSTEM, is thrilled ...

Thumbnail-Photo: Fashion retail: mobile discovery, more convenient shopping...
04.07.2024   #online trading #brick and mortar retail

Fashion retail: mobile discovery, more convenient shopping

How Breuninger is breaking boundaries with omnichannel

Breuninger, with twelve stores in Germany and another in Luxembourg, provides a traditional shopping experience ...

Thumbnail-Photo: Introducing the Salto Glass XS Reader Series...
10.07.2024   #RFID (radio frequency identification) #access control systems

Introducing the Salto Glass XS Reader Series

Redefining Smart Access Control

Salto proudly unveils the Glass XS Reader Series, an innovative line of products ...

Thumbnail-Photo: Intelligent shopping assistant: how can it help in the store?...
26.06.2024   #brick and mortar retail #app

Intelligent shopping assistant: how can it help in the store?

Practical examples of use in DIY stores and fashion stores

Product search, navigation, shopping basket management and checkout: intelligent shopping assistants can now be integrated into ...

Thumbnail-Photo: Successful customer loyalty in times of change: how to win with...
31.07.2024   #brick and mortar retail #sustainability

Successful customer loyalty in times of change: how to win with omnichannel

Challenges and trends in a cross-channel strategy

How has customer loyalty changed? Why is a well thought-out omnichannel strategy crucial ...

Thumbnail-Photo: Cash Management with the apg® Note Acceptor...
06.08.2024   #security #cashpoints

Cash Management with the apg® Note Acceptor

Stand-alone or as addition to the smarttill® Suite

Theft and counterfeit fraud are significant threats to retailers, underscoring the need for secure cash management solutions.For reliable bill validation and secure storage of high-volume bills, the apg® Note Acceptor is an essential tool. It ...

Supplier

apg Solutions EMEA Ltd.
apg Solutions EMEA Ltd.
4 The Drove
BN9 0LA Newhaven
Innovative Technology Ltd.
Innovative Technology Ltd.
Innovative Business Park
OL1 4EQ Oldham
SALTO Systems GmbH
SALTO Systems GmbH
Schwelmer Str. 245
42389 Wuppertal
Zebra Technologies Germany GmbH
Zebra Technologies Germany GmbH
Ernst-Dietrich-Platz 2
40882 Ratingen