Samsung Pay Service Reportedly Open to Hacking; Samsung Responds

Advertisement
By Shekhar Thakran | Updated: 10 August 2016 14:48 IST
Highlights
  • Samsung says "multiple difficult conditions" required for hack to work
  • Samsung says payment service carries same risk as other payment options
  • Hacker claimed that patterns used to create tokens can be figured out
In a presentation given at Defcon, an ethical hacker named Salvador Mendoza highlighted what he believed to be major vulnerabilities associated with the Samsung Pay mobile payment service. He claims that the Samsung Pay service can be misused if payment tokens are skimmed. Samsung has responded to claims made by Mendoza, and has said that even though it is possible to exploit the vulnerability, it is an extremely difficult task to pull off.

In his presentation, Mendoza has shown how the payment tokens that are generated during the usage of Samsung Pay can be intercepted or (less credibly) even be fabricated by hackers to exploit users of Samsung's mobile payment service.

Mendoza's presentation showed how the payment tokens can be skimmed or intercepted. Tokens are sent from the mobile device to the payment terminal, implying the hacker needs to be standing close by. Since the tokens are single-use only, and expire within 24 hours, the payment will need to be halted after authentication for the token to remain valid and be misused. He even claims that the payment token generated by the South Korean company can be hypothetically figured out, and then used to develop tokens that can make purchases. However, Mendoza does not say he was able to generate any fake tokens himself.

Samsung in an FAQ responds to Mendoza's Defcon presentation says that "token skimming" can be exploited, however, "multiple difficult conditions must be met", which include close proximity to the user - as MST is a very short range communication system. The hacker will also have to either jam the signal before it reaches the payment terminal for the token to remain usable, or, somehow trick the user to stop the transaction after authentication. If despite all this, a hacker manages to get hold of a usable payment token, as soon as a transaction is made with it, the user will be notified on the associated smartphone - allowing them to alert authorities. As The Verge points out however, the entire process could be as simple as "setting up a fake payment terminal in a shop."

Advertisement

The company has further clarified that the entire process of stealing and using payment tokens can apply to other payment systems as well - something that Mendoza himself admits to ZDNet - such as debit, credit, and payment cards.

As for the claim that hackers will be able to generate their own Samsung Pay payment tokens after analysing patterns, Samsung responded by saying, "It is important to note that Samsung Pay does not use the algorithm claimed in the Black Hat presentation to encrypt payment credentials or generate cryptograms."
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. These Motorola Phones in India Can Now Download Android 17 Beta 1
  2. Nothing Phone 4a Pink Colour Variant Revealed Before March 5 Launch
  3. Here's When the Realme C83 5G Will Debut in India
  4. Here's How Much the Samsung Galaxy S26 Series Costs Around the World
  5. Perplexity Computer Unveiled With These Advanced AI Workflow Features
  6. Here's When the Motorola Edge 70 Fusion Will Launch in India
  7. iQOO Z11x 5G Will Launch in India Soon With These Features
  8. Vivo X300 Ultra, Vivo X300 FE Bag SDPPI Certification, Could Launch Soon
  9. Motorola Razr Fold Set to Take on Honor Magic V6 at MWC 2026
  10. Vivo V70 Elite, Vivo V70 Go on Sale at This Price in India: See Offers
  1. Realme Narzo Power 5G India Launch Date Announced, Will Be Second Phone With 10,001mAh Battery
  2. Vivo V70 Elite, Vivo V70 With 6,500mAh Battery, 50-Megapixel Cameras Go on Sale in India: Price, Offers
  3. Asus ROG Flow Z13-KJP, ProArt GoPro Edition and TUF Gaming A14 (2026) Launched in India; Price, Features
  4. Perplexity Computer Unveiled as Unified, Multi-Model AI Workflow Platform: Key Features, Availability
  5. Motorola Edge 70 Fusion India Launch Date Announced; Will Arrive After MWC 2026
  6. Vivo X300 Ultra Moniker Revealed as Handset Bags Indonesia's SDPPI Certification Alongside Vivo X300 FE
  7. iQOO Z11x 5G India Launch, Price Teased; Key Specifications Including Dimensity 7000 Series Chip Revealed
  8. Apple Borivali Now Open for Customers as Mumbai’s Second Apple Store After BKC
  9. Apple’s Rumoured Low-Cost MacBook Tipped to Miss Out on True Tone Display, Fast Charging Support
  10. Motorola Razr Fold Set to Take on Honor Magic V6 at MWC 2026; More Details to Be Revealed on March 2
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.