US Warns Retailers About Hacking Software

Advertisement
By Associated Press | Updated: 23 August 2014 09:50 IST
More than 1,000 U.S. retailers could be infected with malicious software lurking in their cash register computers, allowing hackers to steal customer financial data, the Homeland Security Department said Friday.

The government urged businesses of all sizes to scan their point-of-sale systems for software known as "Backoff," discovered last October. It previously explained in detail how the software operates and how retailers could find and remove it.

Earlier this month, United Parcel Service said it found infected computers in 51 stores. UPS said it was not aware of any fraud that resulted from the infection but said hackers may have taken customers' names, addresses, email addresses and payment card information.

Advertisement

The company apologized to customers and offered free identity protection and credit monitoring services to those who had shopped in those 51 stores.

Backoff was discovered in October, but according to the Homeland Security Department the software wasn't flagged by antivirus programs until this month.

Advertisement

Jerome Segura, a senior security researcher at cyber-security software firm Malware Bytes, said that the way that Backoff works is not unique. The program gains access to companies' computers by finding insufficiently protected remote access points and duping computer users to download malware, tricks that have long been in use and are often automated.

What has changed, Segura said, is that the hackers deploying it have become increasingly sophisticated about identifying high-value computer systems after they've broken into them.

Advertisement

"Once the bad guys realized they were able to penetrate larger networks, they saw the opportunity to develop malware that's specifically for credit cards and can evade antivirus programs," he said.

By using Backoff selectively, rather than distributing it widely on the Internet, the hackers likely managed to escape detection for longer. Following Homeland Security's warnings in July, however, companies are much better able to probe their own computers for Backoff.

Advertisement

The battle between retailers and hackers is an ongoing one. Retail giant Target, based in Minneapolis, was targeted by hackers last year and disclosed in December that a data breach compromised 40 million credit and debit card accounts between Nov. 27 and Dec. 15. On Jan. 10, it said hackers stole personal information - including names, phone numbers and email and mailing addresses - from as many as 70 million customers.

Target, the third-largest retailer, has been overhauling its security department and systems in the wake of the pre-Christmas data breach, which hurt profits, sales and its reputation among shoppers worried about the security of their personal data. Target is now accelerating its $100 million plan to roll out chip-based credit card technology in all of its nearly 1,800 stores.

So-called chip and pin technology would allow for more secure transactions than the magnetic strip cards that most Americans use now. The technology has already been adopted in Europe and elsewhere.

Though improving card technology and updating malware detection will help retailers defend themselves, Segura said that the recent profusion of computer breaches should make companies think harder about how they use remote access systems for employees and vendors. By limiting what portions of their systems can be accessed remotely, he said, companies can limit the damage that hackers can do.

"This past year and a half has been breach after breach," he said. "It's incredible."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Xiaomi 17 Series Goes on Sale in India: See Price, Offers
  2. Poco X8 Series Arrives in India With 50-Megapixel Camera: See Price
  3. Oppo A6s 5G With 6,500mAh Battery Launched in India: See Price
  4. Realme P4 Lite 5G Roundup: Price in India, Specifications Expected
  5. Oura Ring 4 Launched as Company's First Smart Ring in India at This Price
  6. iQOO 15R Review
  7. OnePlus 15T Will Be Launched in China Next Week, Company Confirms
  8. Vivo X300 Ultra, Vivo X300s Will Feature This New Colour Technology
  9. Apple Reportedly Increases Foldable iPhone Panel Orders to 20 Million
  10. Oppo Find N6 Launched With Snapdragon 8 Elite Gen 5 SoC, 6,000mAh Battery
  1. Powerbeats Pro 2 Nike Special Edition Launched in India With Apple's H2 Chip, ANC
  2. Xiaomi 17, Xiaomi 17 Ultra With Leica Optics and Snapdragon 8 Elite Gen 5 Chip Go on Sale in India: Price, Offers
  3. Huawei MatePad 11.5 Price in India, Launch Teased Along With Key Specifications
  4. Oppo A6s 5G Launched in India With 6,500mAh Battery, MediaTek Dimensity 6300 SoC: Price, Specifications
  5. Adobe, Nvidia Join Hands to Build the Next Generation of Firefly Models
  6. Amazon Rolls Out 1-Hour and 3-Hour Delivery Across Several US Cities and Towns
  7. Vivo X300 Ultra, Vivo X300s Teased to Feature New 'BluePrint Native' Colour Technology
  8. Samsung Galaxy A57 5G, Galaxy A37 5G Camera Configurations and Pricing Details Leaked
  9. Jio Reportedly Offers Free Incoming SMS Over VoWiFi Without Roaming Pack for International Travellers
  10. OnePlus 15T China Launch Date Announced for March 24; to Be Available in Five RAM, Storage Variants
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.