The Register® — Biting the hand that feeds IT

Feeds

Grocery terminals slurped payment card data

Two months undetected

Agentless Backup is Not a Myth

Grocery chain Aldi Inc. has warned customers in 11 states that their payment card data may have been slurped up by point-of-sale terminals that were illegally planted by identity thieves.

The tampered terminals were in use from June 1 to August 31 in an undisclosed number of stores, the company disclosed in a press release (PDF) that appeared on a Friday, a favorite day of the week for releasing bad news. As many as 1,000 Aldi shoppers in Illinois and Indianapolis have already reported fraudulent charges, according to Computer World.

The breach is noteworthy for the breadth of the affected geography, which spanned from New York state to Georgia to as far west as Illinois. Presumably, those responsible would have had to travel to each store to physically plant the hardware used to siphon personal identification numbers, card numbers and names.

PINs are generally encrypted as they pass from the terminal to the payment processor, so they have to be captured using cameras or keyboard overlays that capture the secret code before it's encrypted.

Aldi, which has about 1,100 stores in 31 states, said it believes all the tampered terminals have been removed. ®

Steps to Take Before Choosing a Business Continuity Partner

This is why the banks are...

Banks have been brainwashing people into thinking that chip and pin is foolproof and the only way there could be problems is if you deliberately tell someone else your pin number, or if you don't cover your pin. They just refuse to accept that there could be dodgy terminals, or that it may be retrieved using some other special techniques. They come on the news when anything happens with chip and pin and say it is the customers' fault. They have deliberately refused to accept that there is a flaw in the system.

11
0

Could me a large number of people hit.

"Presumably, those responsible would have had to travel to each store to physically plant the hardware used to siphon personal identification numbers, card numbers and names."

No, I expect the terminals were modified before they were shipped to the store. Some place between where they were made (likely China) and final distribution. The same thing was reported in the UK some time ago.

The skimming terminals were active for months, they could have collected a lot of card details before they started using them (and the scam was detected).

4
0

stick to cash

It is my favourite near field payment method, and if you move your hands carefully it can be contactless too!!!

3
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?