How Do Fraudsters Attack Payment Systems?

589 views
β€’
March 26, 2012
by
RSAC Cybersecurity
YouTube video player
How Do Fraudsters Attack Payment Systems?

TL;DR

Fraudsters compromise payment systems by exploiting weak point-of-sale configurations, unchanged default passwords, open ports, remote desktop access, skimming devices, malicious attachments, and human behavior. Organizations can reduce exposure through annual risk assessments, layered controls, stronger user and transaction authentication, customer education, rapid law enforcement involvement, and prompt forensic investigation after a breach.

Transcript

Hey, thank you very much. I'm Tom Field. I'm the editorial director with Information Security Media Group, and I want to introduce my partner today. How are you? I'm, uh, Eric Rasmussen with the, uh, Secret Service out of our Cyber Intelligence section in Washington, DC. We got a lot to talk about today, and we're gonna try to condense this into ju... Read More

Key Insights

  • Payment fraud is increasingly directed at ATMs, vestibule access readers, point-of-sale devices, gas pumps, payment cards, and online bank accounts. A compromised vestibule reader can capture card data from everyone entering the area, expanding the potential impact beyond a single ATM.
  • Point-of-sale systems are vulnerable when retailers leave default passwords, default settings, open ports, or remote desktop access unchanged. The presentation identifies basic installation and configuration failures as major reasons attackers can compromise retail payment environments and distribute stolen information around the globe.
  • Payment-system attacks follow three basic stages: ingress, collection, and egress. Attackers enter through a vulnerability, gather payment information, and remove the data, while alternative investigative terms such as infiltration, aggregation, and exfiltration describe essentially the same sequence.
  • Food and beverage businesses are the most frequently affected victims discussed in the presentation. Restaurants, gift shops, and small food vendors commonly use point-of-sale systems, and weak default configurations can contribute to thousands of attacks per week and dozens of daily investigative leads.
  • The human element remains a primary security vulnerability even when organizations invest in authentication tokens, technical tools, and cyber defenses. Attackers may exploit an end user through a malicious email attachment instead of directly defeating the underlying machine or security system.
  • Insider risk includes both malicious and inadvertent behavior. An employee can unintentionally become an insider threat by opening a malicious attachment, installing malware, and allowing internal organizational information to leak to an external attacker without deliberately participating in the crime.
  • Banking guidance calls for online banking risk assessments at least annually, layered security controls across transactions, improved user and transaction authentication, and stronger customer education. These measures distribute protection across multiple barriers instead of relying on a single control to stop fraudsters.
  • Breach response depends on speed because sophisticated hackers can enter and leave quickly while creating a limited forensic footprint. Affected organizations should determine how attackers entered, identify vulnerabilities and evidence, contact law enforcement immediately, and engage a third-party forensic firm.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How do fraudsters compromise point-of-sale systems?

Fraudsters compromise point-of-sale systems by exploiting weak retail configurations, including unchanged default passwords, default settings, open vulnerable ports, and available remote desktop access. After gaining entry, they collect payment data and remove it from the environment. The presentation summarizes this method as ingress, collection, and egress, although investigators may use terms such as infiltration, aggregation, and exfiltration.

Q: Why are retail payment systems vulnerable to fraud?

Retail payment systems are vulnerable because they may be installed as plug-and-play systems without strong security configuration. The person installing or managing the system may fail to replace default passwords, adjust default settings, close vulnerable ports, or disable unnecessary remote desktop access. These weaknesses give attackers practical entry points for stealing payment information and distributing it beyond the compromised business.

Q: How does ATM and vestibule skimming steal card data?

ATM skimming uses a device placed on an ATM to capture information when a customer inserts a payment card. Fraudsters may also compromise the card reader used to enter an ATM vestibule. That approach can collect data from everyone who swipes a card to enter, rather than limiting the theft to customers using one particular ATM inside the vestibule.

Q: What is the inadvertent insider threat?

The inadvertent insider threat occurs when someone within an organization unintentionally enables an external compromise. An employee may receive a malicious email, open a harmful attachment, and download malware. Information from inside the organization can then leak outward even though the employee did not intend to steal data or cooperate with the attacker. This differs from deliberate, malicious insider theft.

Q: Why is the human element difficult to secure?

The human element is difficult to secure because attackers can exploit end users instead of directly breaking a machine or defeating a technical control. Organizations may invest in authentication tokens, tools, and other cyber defenses, yet a person can still respond to deception or open a malicious attachment. The presentation argues that humans remain present and therefore remain a primary source of vulnerability.

Q: What security controls can financial institutions use against online fraud?

Financial institutions can assess online banking risks at least annually and deploy layered security controls throughout transactions. They can strengthen both user authentication and transaction authentication rather than relying on one barrier. They can also educate commercial and consumer customers about relevant threats, the controls available to them, and the actions they can take to reduce their exposure to fraudulent activity.

Q: What should a business do after discovering a payment breach?

A business should quickly determine how the attackers entered, identify the vulnerabilities they exploited, and preserve evidence remaining on affected machines. Law enforcement should be involved from the beginning, whether through a local Secret Service office, FBI office, or fraud detective. The merchant should also engage a third-party forensic firm because sophisticated hackers may move quickly and leave only a small footprint.

Q: Why must payment fraud investigations begin quickly?

Payment fraud investigations must begin quickly because sophisticated attackers can enter a system, collect data, and leave in a short period while preserving little evidence of their activity. Although organizations may assume evidence will remain on servers, delays can make reconstruction harder. Prompt law enforcement involvement and forensic examination improve the effort to identify the entry method, vulnerabilities, and traces left on compromised machines.

Summary & Key Takeaways

  • Financial fraud increasingly targets ATMs, vestibule card readers, gas pumps, retail terminals, payment cards, and online bank accounts. Skimming can capture data from individual machines or everyone entering an ATM vestibule. These schemes are becoming more sophisticated, organized, persistent, and damaging to merchants, financial institutions, payment processors, and customers.

  • Point-of-sale systems are attractive targets because retailers may install them with default passwords, default settings, open ports, and remote desktop access unchanged. Attackers follow a simple pattern: gain entry, collect payment data, and remove it. Food and beverage businesses were described as the most frequently affected victim category.

  • Defensive measures include annual online banking risk assessments, layered security throughout transactions, improved user and transaction authentication, and customer education. After discovering a compromise, organizations should identify the entry method, vulnerabilities, and remaining evidence, then quickly involve law enforcement and a third-party forensic firm because sophisticated attackers may leave little evidence behind.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š