El Reg is running a story (based on a Telegraph article) describing trojaned POS (Point Of Sale) terminals. Apparently during manufacture or shortly after (and before shipment) the chip-and-pin devices were modified to send account details "overseas" (Pakistan is named). (Europe has a high penetration of smart cards that act as currency/credit cards unlocked at the time of purchase by a PIN the owner enters on a device at the store.)
The perpetrators apparently wait a couple of months after getting the data before making fraudulent transactions, making it harder to determine what's going on.
Much like the Cisco issue this highlights supply-chain control problems.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment