Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Targeted by Hackers in a Credit Card Breach
News & Analysis

Targeted by Hackers in a Credit Card Breach

ISBuzz TeamBy ISBuzz TeamNovember 27, 2015Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Brazilian Bank Users Are the Targets of a New BrasDex Malware
Brazilian Bank Users Are the Targets of a New BrasDex Malware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Major customer data breach due to malware in their POS system, and many other high-profile hotel breaches recently (Starwood, Trump Hotels)  – where are the hotels going wrong? This week also saw the discovery of one of the most sophisticated retail PoS malware ever, ModPos, just in time for the holiday shopping season. Are we likely to see more PoS breaches in the coming days and weeks? What can businesses and consumers do to protect themselves? Security experts from Proofpoint, Voltage, and Tripwire have the following comments on it.

[su_note note_color=”#ffffcc” text_color=”#00000″]Mark Bower, Global Director of Product Management, Enterprise Data Security for HPE Security :

“Once again, with confirmation late yesterday of a payment card data breach at Hilton Hotels and last week Starwood, we see that hospitality service providers, like retailers, face extraordinary challenges with customer data security at point of sale (POS).

GammaPOS, Abaddon, Dexter, the newly discovered ModPOS and other retail malware are designed to steal clear data in memory from POS applications, resulting in the loss of magstripe data, EMV card data or other sensitive data exposed at the point of sale.

POS systems are often the weak link in the chain. They should be isolated from other networks, but often are connected. A checkout terminal in constant use is usually less frequently patched and updated, and is thus vulnerable to all manner of malware compromising the system to gain access to cardholder data.

However it’s important to note, especially going into the busy holiday season, that retailers, hospitality and any businesses using POS systems, can avoid the impact of these types of advanced attacks. Proven methods are available to neutralize data from breaches either at the card reader, at the point of sale, in person or online. Leading retailers and payment processors have adopted these data-centric security techniques with huge positive benefits: reduced exposure of live data from the reach of advanced malware during an attack, and reduced impact of increasingly aggressive PCI DSS 3.1 compliance enforcement laws, laws aimed at making data security a ‘business as usual’ matter for any organization handling card payment data.

The good news is that savvy merchants are already tackling this risk and giving the malware nothing to steal through solutions that also have a dramatic cost reducing benefit to PCI compliance. Encrypting the data in the card reading terminal ahead of the POS eliminates the exposure of live information in vulnerable POS systems. The attackers get only useless encrypted data. No live data means no gold to steal. Attackers don’t like stealing straw.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]George Rice, Senior Director, Payments at HPE Security :

Tips for retailers

“Only collect customer data that you need and can adequately protect. Why do you need date-of-birth or social security numbers, for example? Encrypt or tokenize everything you determine to be mission-critical.

Protect data at the moment of submission by the customer. Criminals know to embed malware near to data acceptance points, like point-of-sale systems or web front-ends.

Only unprotect data when absolutely necessary. A high percentage of the time, applications and users can work equally well with a surrogate value.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Dwayne Melancon, CTO of Tripwire :

“As holiday travel and vacations hit their peak, cyber criminals will be targeting many businesses including hotel chains. If they haven’t done so already, hotel chains should assess their networks to isolate their point-of-sale (POS) devices as much as possible from non-payment portions of their networks. Additionally, it is vital that any business who relies on point-of-sale technology use a security system that can continuously monitor their systems to understand what a normal configuration looks like, so any suspicious changes to the point-of-sale system can be detected immediately and dealt with before a loss occurs.”

For consumers, Tripwire’s team of security researchers recommends that consumers take the following precautions when shopping online this holiday season:

  1. Beware of the siren song of a great deal by avoiding shopping websites that offer prices that seem too good to be true. Cyber criminals frequently use extremely low prices on popular items to draw in potential victims.
  2. Use a credit card instead of a debit card. If your credit card data is used for something nefarious, it’s easier to resolve issues with a credit card company than with your bank.
  3. Take advantage of the alert features on your credit card, which can warn you of abnormal account activity. Alerts are helpful any time during the year, but they are especially useful during busy holiday shopping seasons.
  4. Never purchase merchandise from a website that does not use secure HTTPS for the purchase process.  Check the address line of your browser during the purchase process; it should start with HTTPS.
  5. Make sure your computer has the most current security software patches installed. Once a security patch is available, cyber criminals have all the information they need to attack devices that have not been updated.

“Online shoppers should also be especially careful of emails they receive,” said Lane Thames, security researcher at Tripwire. “Phishing campaigns that try to dupe consumers into giving away personal and financial information tend to rise during the holiday season.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Kevin Epstein, VP of Threat Operations at Proofpoint :

What is the best advice for customers who believe they may have been impacted?

“In the short-term, consumers can take immediate defensive actions by placing a ‘fraud lock’ or ‘credit freeze’ on their credit records; that would mitigate the financial aspects of identity theft.”

How much money do you expect the cyber criminals can make with this stolen data?

“Criminals will likely make less than Hilton Worldwide will lose in terms of lost sales, costs of consumer notification, breach cleanup and the like — but the credit-card numbers alone, sold online, could be worth double-digits apiece even before being used to tap consumer lines of credit. This theft could easily net the initial attackers many millions of dollars, with subsequent fraudulent use of the cards raising that by an order of magnitude or more.”

Do you have any advice on how Hilton Worldwide should handle the fallout of the breach?

“Notification of impacted consumers and sponsorship of appropriate protection is a clear priority.  Cyberattacks’ most expensive aspect isn’t cleanup; it’s brand damage. Restoring consumer confidence is paramount. To that end, subsequent disclosure of the attack source and implementation of new, modern protective systems to prevent recurrence are also good steps to take, quickly.”[/su_note]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}