Tag Archive for: PointofSale

FBI Raids Chinese Point-of-Sale Giant PAX Technology – Krebs on Security


U.S. federal investigators today raided the Florida offices of PAX Technology, a Chinese provider of point-of-sale devices used by millions of businesses and retailers globally. KrebsOnSecurity has learned the raid is tied to reports that PAX’s systems may have been involved in cyberattacks on U.S. and E.U. organizations.

FBI agents entering PAX Technology offices in Jacksonville today. Source: WOKV.com.

Headquartered in Shenzhen, China, PAX Technology Inc. has more than 60 million point-of-sale terminals in use throughout 120 countries. Earlier today, Jacksonville, Fla. based WOKV.com reported that agents with the FBI and Department of Homeland Security (DHS) had raided a local PAX Technology warehouse.

In an official statement, investigators told WOKV only that they were executing a court-authorized search at the warehouse as a part of a federal investigation, and that the inquiry included the Department of Customs and Border Protection and the Naval Criminal Investigative Services (NCIS). The FBI has not responded to requests for comment.

Several days ago, KrebsOnSecurity heard from a trusted source that the FBI began investigating PAX after a major U.S. payment processor started asking questions about unusual network packets originating from the company’s payment terminals.

According to that source, the payment processor found that the PAX terminals were being used both as a malware “dropper” — a repository for malicious files — and as “command-and-control” locations for staging attacks and collecting information.

“FBI and MI5 are conducting an intensive investigation into PAX,” the source said. “A major US payment processor began asking questions about network packets originating from PAX terminals and were not given any good answers.”

KrebsOnSecurity reached out to PAX Technology’s CEO on Sunday. The company has not yet responded to requests for comment.

The source said two major financial providers — one in the United States and one in the United Kingdom — had already begun pulling PAX terminals from their payment infrastructure, a claim that was verified by two different sources.

“My sources say that there is tech proof of the…

Source…

DMSniff Point-of-Sale Malware Silently Attacked SMBs For Years – BleepingComputer

DMSniff Point-of-Sale Malware Silently Attacked SMBs For Years  BleepingComputer

A Point-of-Sale (POS) malware which uses a domain generation algorithm to create command-and-control domains on the fly was detected in attacks against …

“malware news” – read more

Forever 21 Finds Point-of-Sale Data Breach at Stores

  1. Forever 21 Finds Point-of-Sale Data Breach at Stores  Los Angeles Business Journal
  2. Forever 21 Reports Findings from Investigation of Payment Card Security Incident  Forever 21
  3. Forever 21 on the Forbes America’s Largest Private Companies List  Forbes
  4. Cybercrime to Cost Global Business Over $ 8 Trillion in the Next 5 Years – Juniper Research  Juniper Research
  5. Full coverage

data breach – Google News

Security researchers demo point-of-sale system hack to buy a MacBook for $1 [Video]

TNW reports that ERPScan researchers Dmitry Chastuhin and Vladimir Egorov found the hack scarily easy to carry out. The key to it is that point-of-sale terminals developed by SAP and Oracle have no encryption or authorization procedures to prevent the …
mac hacker – read more