Skip to content
europatentbox

europatentbox

The Profession

Primary Menu europatentbox

europatentbox

  • Business & Finance
  • Business News
  • eCommerce
  • Business Education
  • Finance
  • Marketing
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
  • Business News

This code hacks nearly every credit card machine in the country

Amy B. Taylor March 26, 2022
Stolen credit card price tag: $102

Get ready for a facepalm: 90% of credit card readers currently use the same password.

The passcode, set by default on credit card machines since 1990, is easily found with a quick Google searach and has been exposed for so long there’s no sense in trying to hide it. It’s either 166816 or Z66816, depending on the machine.

With that, an attacker can gain complete control of a store’s credit card readers, potentially allowing them to hack into the machines and steal customers’ payment data (think the Target (TGT) and Home Depot (HD) hacks all over again). No wonder big retailers keep losing your credit card data to hackers. Security is a joke.

This latest discovery comes from researchers at Trustwave, a cybersecurity firm.

Administrative access can be used to infect machines with malware that steals credit card data, explained Trustwave executive Charles Henderson. He detailed his findings at last week’s RSA cybersecurity conference in San Francisco at a presentation called “That Point of Sale is a PoS.”

Take this CNN quiz — find out what hackers know about you

The problem stems from a game of hot potato. Device makers sell machines to special distributors. These vendors sell them to retailers. But no one thinks it’s their job to update the master code, Henderson told CNNMoney.

“No one is changing the password when they set this up for the first time; everybody thinks the security of their point-of-sale is someone else’s responsibility,” Henderson said. “We’re making it pretty easy for criminals.”

Trustwave examined the credit card terminals at more than 120 retailers nationwide. That includes major clothing and electronics stores, as well as local retail chains. No specific retailers were named.

The vast majority of machines were made by Verifone (PAY). But the same issue is present for all major terminal makers, Trustwave said.

verifone credit card reader
A Verifone card reader from 1999.

A spokesman for Verifone said that a password alone isn’t enough to infect machines with malware. The company said, until now, it “has not witnessed any attacks on the security of its terminals based on default passwords.”

Just in case, though, Verifone said retailers are “strongly advised to change the default password.” And nowadays, new Verifone devices come with a password that expires.

In any case, the fault lies with retailers and their special vendors. It’s like home Wi-Fi. If you buy a home Wi-Fi router, it’s up to you to change the default passcode. Retailers should be securing their own machines. And machine resellers should be helping them do it.

Trustwave, which helps protect retailers from hackers, said that keeping credit card machines safe is low on a store’s list of priorities.

“Companies spend more money choosing the color of the point-of-sale than securing it,” Henderson said.

This problem reinforces the conclusion made in a recent Verizon cybersecurity report: that retailers get hacked because they’re lazy.

The default password thing is a serious issue. Retail computer networks get exposed to computer viruses all the time. Consider one case Henderson investigated recently. A nasty keystroke-logging spy software ended up on the computer a store uses to process credit card transactions. It turns out employees had rigged it to play a pirated version of Guitar Hero, and accidentally downloaded the malware.

“It shows you the level of access that a lot of people have to the point-of-sale environment,” he said. “Frankly, it’s not as locked down as it should be.”

Flappy Bird... on a payment terminal?

CNNMoney (San Francisco) First published April 29, 2015: 9:07 AM ET

Tags: Amazon Business Login, Amazon Business Prime, Bank Of America Business Account, Best Business Schools, Business Attorney Near Me, Business Bank Account, Business Card Holder, Business Card Maker, Business Card Template, Business Cards Near Me, Business Casual Attire, Business Casual Shoes, Business Casual Woman, Business Plan Examples, Ca Business Search, Ca Sos Business Search, Capital One Business Credit Card, Chase Business Checking, Chase Business Credit Cards, Chase Business Customer Service, Chase Business Login, Chase Business Phone Number, Cheap Business Cards, Citizens Business Bank, Cox Business Login, Digital Business Card, Facebook Business Suite, Finance In Business, Free Business Cards, Google Business Login, Harvard Business School, Lands End Business, Massage Parlor Business Near Me, Michigan Business Entity Search, Mind Your Business, Mind Your Own Business, Ohio Business Search, Risky Business Costume, Skype For Business, Small Business Loan, Small Business Saturday 2021, Starting A Business, Texas Business Entity Search, Triumph Business Capital, Vending Machine Business, Verizon Business Customer Service, Vonage Business Login, Wells Fargo Business Account, Yahoo Small Business, Yahoo Small Business Login

Continue Reading

Previous Uber strikes groundbreaking deal with NYC taxi industry
Next Britain’s SME’s celebrated at inaugural Business Champion Awards

More Stories

man in a wheelchair holding a computer tablet
  • Business News

Client Onboarding Checklist for Agencies

Amy B. Taylor September 20, 2023 0
How do you hire an SEO manager
  • Business News

How do you hire an SEO manager?

Amy B. Taylor September 14, 2023 0
  • Business News

Why do you need an auditor in Guatemala?

Amy B. Taylor September 10, 2023 0
September 2023
M T W T F S S
 123
45678910
11121314151617
18192021222324
252627282930  
« Aug    

Archives

Recent Posts

  • Shell’s bid to conduct offshore seismic surveys hits another legal obstacle
  • T.J. House Reveals He Is Gay And Announces Engagement
  • How to develop your accountancy practice’s competitive advantage
  • Google Ads Shift, Explained | Marketing
  • Digital Technology and Social Media’s Impact on Adolescent Well-Being

BL

Tags

Amazon Business Login Amazon Business Prime Att Business Login Bank Of America Business Account Best Business Schools Business Business Attorney Near Me Business Bank Account Business Card Holder Business Card Maker Business Cards Near Me Business Card Template Business Casual Attire Business Casual Shoes Business Casual Woman Business Plan Examples Ca Business Search Capital One Business Credit Card Ca Sos Business Search Chase Business Checking Chase Business Credit Cards Chase Business Customer Service Chase Business Login Chase Business Phone Number Cheap Business Cards Citizens Business Bank Cox Business Login Digital Business Card Facebook Business Suite Finance In Business Free Business Cards Google Business Login Harvard Business School Lands End Business Massage Parlor Business Near Me Michigan Business Entity Search Mind Your Business Mind Your Own Business Ohio Business Search Risky Business Costume Skype For Business Small Business Loan Small Business Saturday 2021 Starting A Business Texas Business Entity Search

Related Article

  • Business & Finance

Shell’s bid to conduct offshore seismic surveys hits another legal obstacle

Amy B. Taylor September 25, 2023 0
T.J. House Reveals He Is Gay And Announces Engagement
  • Mental Health Related

T.J. House Reveals He Is Gay And Announces Engagement

Amy B. Taylor September 24, 2023 0
  • Education

How to develop your accountancy practice’s competitive advantage

Amy B. Taylor September 22, 2023 0
Google Ads Shift, Explained | Marketing
  • Education

Google Ads Shift, Explained | Marketing

Amy B. Taylor September 21, 2023 0
Digital Technology and Social Media’s Impact on Adolescent Well-Being
  • Uncategorized

Digital Technology and Social Media’s Impact on Adolescent Well-Being

Amy B. Taylor September 21, 2023 0
europatentbox.com | CoverNews by AF themes.

WhatsApp us