Home > Security News > Credit card thieves target small merchants, flawed POS systems, study finds
Security News:
EMAIL THIS

Credit card thieves target small merchants, flawed POS systems, study finds

By Marcia Savage, features editor, Information Security magazine
29 Apr 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

More often than not, attackers who aim to steal credit card data are targeting small, brick-and-mortar merchants and exploiting vulnerable point-of-sale (POS) systems, according to a study recently released by Trustwave.

The primary offender has been the point-of-sale vendors themselves, who are often contracted by the merchant to remotely manage and maintain the devices and software they sell to the merchants.
Roger Nebel,
PCI DSS auditor, director of strategic security, FTI Consulting

Trustwave, a Chicago-based Payment Card Industry Data Security Standard (PCI DSS) assessor, looked at 350 payment card compromises in 14 countries between January 2006 and December 2007. The company said the study counters the popular perceptions that using credit cards online is less safe than at a physical store, and that attackers target large merchants for their wealth of data.

Seventy-percent of the compromises occurred at brick-and-mortar merchants, and 92% of the merchants were Level 4, meaning they handle less than 1 million credit card transactions annually. More than half of the compromises Trustwave investigated occurred in the food service industry.

Small stores and restaurants don't have as many resources for security as large merchants and e-commerce shops, and may use POS systems that are improperly configured by a third party, according to Trustwave. In 64% of the breaches, negligence by a third-party such as an integrator may have contributed.

For example, a pizza restaurant might hire a local company to set up a POS system that also provides services like placing orders, said Nicholas Percoco, Trustwave vice president of consulting. Instead of dialing up for credit card authorizations, the device is connected to the Internet. "The people who set up the systems for the restaurant are not savvy about information security and do things like not install a firewall between the Internet and the POS system, or they don't install antivirus," he said.

Another common problem is that the contractor uses an unsecured remote access system to support the merchant's network and POS devices. The systems often use blank, default or easily guessable passwords, Percoco said. In addition, Trustwave has seen many old POS devices that have no traditional security controls and store cardholder data that's prohibited by PCI DSS. It's relatively easy for an attacker to configure a port scanner to look for vulnerable POS devices and break into them, Percoco said.

"We've seen a batch of cases in one city, where the commonality between those merchants is that they all use the same POS system, the same integrator and the same Internet service provider," he said.

PCI DSS news and tips:
Are there any references that discuss the cost of PCI DSS compliance? Security expert Mike Rothman discusses the expenses related to complying with PCI DSS.

Should PCI DSS auditors be subjective? In this expert Q&A, security pro Mike Rothman discusses whether or not a PCI DSS audit should be subjective.

PCI compliance costs often underestimated, study finds: Companies are moving forward with PCI DSS projects, but many are underestimating the costs associated with compliance.

PCI Council issues clarification on Web application security: The PCI Security Standards Council released documentation hoping to reduce a tide of confusion over enforcement of application firewalls and code reviews.

Roger Nebel, an independent PCI DSS auditor and director of strategic security at FTI Consulting, said he's also seen many payment card breaches involving third parties and misconfigured remote access systems.

"The primary offender has been the point-of-sale vendors themselves, who are often contracted by the merchant to remotely manage and maintain the devices and software they sell to the merchants," he said. "We see default user IDs and passwords, which the bad guys all know."

But Nebel criticized other findings in the Trustwave report. Without saying how many credit card numbers were compromised in the breaches, the analysis is faulty, he said. "We don't know the relative size of the harm. There's no way to understand if the 92% being Level 4 is meaningful."

There's also the issue of self-selecting response, which weakens the study, he added: "The fact they've done 350 investigations and most are Level 4 merchants could be that the Level 4 merchants chose them and the Level 1 merchants didn't."

Gary Palgon, vice president of product management at nuBridges, a supplier of secure connectivity products and a member of the PCI Security Standards Council, said some the study's findings need to be balanced by taking a larger view of the market. Breaches of Level 4 merchants are on a small scale compared to the compromise of a larger merchant like the Hannaford Bros. Co. supermarket chain, in which thieves stole 4.2 million payment card numbers, he said.

The new Payment Application Data Security Standard (PA-DSS), released April 15 by the PCI Security Standards Council, will help ensure the security of POS devices, Palgon and others said.

Based largely on Visa's Payment Application Best Practices (PABP) program and supported by the five major payment card brands, the standard provides a global set of security requirements for payment applications such as POS systems. It will ensure payment applications don't store sensitive card data and aren't rife with flaws, PCI officials have said. Visa previously issued a July 2010 deadline for banks to ensure their merchants use only PABP-compliant applications.

Michael Petitti, Trustwave's chief marketing officer, said Level 4 merchants may number around 6.5 million in the U.S. "They're small, probably card-present environments reliant on a third party to configure those environments. So there are many moving parts that need to be addressed, which requires a lot of education and awareness that the industry is just getting around to."



Tags: PCI Data Security StandardData Privacy and ProtectionIdentity Theft and Data Security BreachesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
PCI Data Security Standard
Chip and PIN adoption
Chip and PIN adoption serves lesson for U.S. payment industry
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Wireless network guidelines for PCI DSS compliance
Visa probes tokens, encryption for PCI card data protection
Feds push cybersecurity jobs, PCI DSS changes ahead.
Voltage, RSA spar over tokenization, data protection
Experts, vendors search for PCI's holy grail

Data Privacy and Protection
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Researchers predict SSNs, crack algorithm putting identities at risk
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Mass. Senate seeks to amend, weaken data breach notification law
Data Privacy and Protection Research

Identity Theft and Data Security Breaches
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Chip and PIN adoption serves lesson for U.S. payment industry
Group to shed light on secure identity management threats
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
University data breach exposes 163,000 women to identity theft
TJX thrives following breach, bucks sour economy

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts