Visa warns that hackers are back at it stealing your C.C. details from gas pumps
When you are traveling this holiday season make sure you are on the look out for more secure fuel stations as Cybercrime groups are actively exploiting a weakness in gas station point-of-sale (POS) networks to steal credit card data, Visa has revealed. The company's fraud disruption teams are investigating several incidents in which a hacking group known as Fin8 defrauded fuel dispenser merchants. In each case, the attackers gained access to the POS networks via malicious emails and other unknown means. They then installed POS scraping software that exploited the lack of security with old-school mag stripes in card readers that can't read chips.
The hack doesn't appear to affect more secure chip cards, but many of the service stations haven't replaced card readers at the pumps yet. So, do not shop at old , out dated stations. Look for stations with new pumps where you have new card readers that you have to enter your card and pin i.d's. In the older machines data is apparently sent in an unencrypted form to the vendor's main network, where the thieves have figured out how to intercept it. The other problem is that the POS systems aren't firewalled off from other, less critical parts of the network, allowing thieves to gain lateral access once the network is breached.
There's not much cardholders can do to avoid the attacks, but Visa has advised fuel merchants to encrypt data while it's transferred or support chip-equipped cards. "Fuel dispenser merchants should take note of this activity and deploy devices that support chip [cards] wherever possible, as this will significantly lower the likelihood of these attacks," it advised in the December security alert.
Earlier this year, Visa announced that fuel merchants must deploy chip readers by October 2020. After that, any service stations without the new tech will be liable for any fraud. The problem is, many such businesses have very old technology and must replace the entire pump at an estimated cost of up to $250,000 per station. Spread across all the convenience stores in the US, the total hit has been estimated at around $22.5 billion on the very high end.
So, for now it is up too us to look out for ourselves as many of the fuel station owners will not do what is needed to up date their own pumps until it is mandated and they are made legally liable. I would suggest we all write the Fuel Companies when we see these stations and report them too the fuel companies. If they loose their franchise for that fuel Shell, Exxon, Chevron, Etc, So Be It. Let's Stand together and make them do the right thing before October 2020!!! MSN Video: Watch Here EDP Staff