Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Oracle’s Data Breach May Explain Spate of Retail Hacks
News & Analysis

Oracle’s Data Breach May Explain Spate of Retail Hacks

ISBuzz TeamBy ISBuzz TeamAugust 12, 2016Updated:July 4, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
PORTSMOUTH, ENGLAND - JULY 23: Oracle Team USA skippered by Jimmy Spithall in action during day two of the Louis Vuitton America's Cup World Series on July 23, 2016 in Portsmouth, England. (Photo by Charlie Crowhurst/Getty Images)
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The systems of the Oracle MICROS payment terminals division have been infected by a malware, systems worldwide are potentially at risk. The attackers infected the troubleshooting portal of the Oracle MICROS payment terminals to steal customers’ login credentials, then use the usernames and passwords to access their accounts and gain control over their MICROS point-of-sales (POS) terminals. IT Security Experts from ESET, Lieberman Software and Imperva commented below.

Mark James, Security Specialist at ESET:

mark-james“Oracle’s MICROS system has been compromised by malware; this could have been a targeted attack through some means of phishing process or just a lucky random catch. Once infected this enabled the usernames and passwords of MICROS customers to be sent off site for potential further malware infiltration. MICROS is believed to have over 330K sites across 180 countries and includes big names in the retail and hospitality industry. When these customers log in to their support website or ticketing system for help the malware would then steal their login credentials enabling the attackers to potentially use those credentials at a later time to spread further malware which may have led to some of the big name breaches we have witnessed in recent months.

As this malware would be very stealthy it may have been there for some time secretly harvesting information without notice, because of the way malware infiltrates and propagates through systems it’s often chance that honey pots like this end up being captured and used for foul means but when they hit the jackpot the rewards can be massive.”

Jonathan Sander, VP of Product Strategy at Lieberman Software:

Jonathan Sander“Though these point-of-sale (POS) machines don’t look it, they’re essentially PCs under the covers. Like every other PC, they are vulnerable to attack by malware. The key problem is that since POS systems aren’t seen as PCs they aren’t protected like they are. Simple security basics like rotating and protecting admin credentials aren’t typically applied to POS systems. Like any other unprotected PCs, this almost ensures they will become a target. People need to see POS systems for what they are: PCs attached to the network handing sensitive customer information. Seen in that light, the PCs we call POS terminals will get the right security attention.”

Itsik Mantin, Director of Security Research at Imperva:

“This security incident against Oracle POS systems shows once again that no system is immune to security breaches. Like in other breaches, there are many unknowns, including 1) the length of time the malware was in the Oracle systems before discovery by the new security tools, 2) which data was stolen and 3) what the attackers have done with the stolen data.

It’s entirely possible that the data stolen in this breach including user credentials has been used to extend the hack into commercial web applications such as shops, hotels, and retail outlets.

This incident is yet again a lesson for any organization that has sensitive information: while attempting to avoid infection and penetration, you must have other plans in place to detect and contain an infection or a breach once it happens. It’s not enough to rely on password policies, which are of no use when the credentials are stolen, to prevent attacks. Those in charge of web applications should be mindful to take specific detection measures to validate the authenticity of login to the system, treating with caution login from unexpected countries or anonymous networks, or logins from a web bot and rate limiting login attempts, in particular, those using credentials known to be stolen.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}