• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechSamsung

Chinese hackers breached LoopPay, the company behind Samsung Pay’s secret sauce

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
October 7, 2015, 5:53 PM ET
An employee demonstrates a Samsung Pay, Samsung's new mobile payment system at a shop in Seoul
An employee demonstrates a Samsung Pay, Samsung's new mobile payment system at a shop in Seoul, South Korea, September 4, 2015. Photograph by Kim Hong-Ji — Reuters

Time to put the party hats away.

Samsung, coming off an incredible quarter for earnings, said one of its subsidiaries whose technology handled the transmission of payment data between the company’s smartphones and merchants’ systems recently suffered a computer network breach.

The company said the attack affected LoopPay, the Mass.-based startup purchased by the South Korean electronics giant for a reported $250 million earlier this year. LoopPay developed part of the secret sauce behind Samsung Pay, the company’s mobile payment wallet which debuted in the U.S. last week.

The New York Times first reported that LoopPay’s corporate network had been targeted by a state-sponsored Chinese hacking group—known as the Codoso Group or Sunshock Group among security professionals—on Wednesday, citing people familiar with the breach investigation, as well as executives at LoopPay and parent Samsung (SSNLF).

A Samsung spokesperson confirmed the breach with Fortune via email, passing along a statement from Darlene Cedres, the company’s chief privacy officer. “Samsung Pay was not impacted and at no point was any personal payment information at risk,” the statement read. “This was an isolated incident that targeted the LoopPay corporate network, which is a physically separate network from Samsung Pay. The LoopPay corporate network issue was resolved immediately and had nothing to do with Samsung Pay.”

The hackers may have been seeking information regarding LoopPay’s intellectual property: magnetic secure transmission, tech that enables Samsung Pay to be compatible with older point-of-sale terminals by mimicking the magnetic strips on payment cards. (Samsung Pay, like competitors Apple (AAPL) Pay and Google’s (GOOG) Android Pay, also works with near-field communications technology, which conducts transactions via radio waves.)

LoopPay’s computer network had been breached as early as March, a month after Samsung acquired the firm, the Times reported. The company did not learn of the intrusion until late August, a month prior to Samsung Pay’s U.S. launch, when another organization stumbled across its data during a separate investigation of the Codoso Group, a sophisticated threat actor that has a history of targeting financial firms, military and defense contractors, C-level executives, and Chinese political dissidents.

John Hultquist, head of cyberespionage threat intelligence at the Dallas, Texas-based security firm iSight Partners, shared his thoughts on the hacking unit with Fortune. “They’re one of the better actors we see coming out of that region,” Hultquist said, noting that the China-based group is known for exploiting sophisticated zero-day vulnerabilities—previously unknown computer bugs—to compromise the machines of their victims. “I don’t believe they were there for criminal interests,” he added. “These guys are not really after monetizable commodity data. They’re after intelligence and esoteric information—information only a few types of people can actually make use of.”

In other words, Hulquist said, the Codoso group is motivated by espionage, both political and economic. The Obama administration recently struck an agreement with Chinese President Xi Jinping during his first state visit to the U.S. that prohibits the two nations from conducting economic espionage against one another. Although many commenters question whether the agreement will hold, the hacking at LoopPay seems to have predated the deal.

“These people may have been after cryptographic information,” Hultquist told Fortune, mentioning that the Codoso Group might have had an interest in “unmasking transactions” to keep tabs on the financial activity of targets of interest. “Their intent was probably to stay low and monitor the network in perpetuity,” he said.

“I think when details finally come out we’ll probably learn that it was a spearphishing attack leveraging a user clinking on a link or opening an attachment,” said Anup Ghosh, founder and CEO of the Fairfax, Va.-based security firm Invincea, describing a common vector for cyber espionage. Invincea researchers have observed the Codoso Group using that attack method before, Ghosh said.

“This compromise probably has less to do with trying to steal money and more to do with this particular actor’s systematic compromise of U.S. tech companies,” he added, noting that these are exactly the kinds of attacks the recent agreement between president Barack Obama and Xi is designed to stop.

Will Graylin, chief exec at LoopPay and co-general manager of Samsung Pay, told the Times that his division hired and retained two private forensics teams on Aug. 21, in response to intrusion.

The one named firm named by the Times, “Sotoria” [sic], a Charleston, S.C.-based incident-response business, was apparently dismissed from LoopPay’s premises three days after being called in. The company was, the Times reported Graylin as saying, looking at systems that “fell outside the scope of the initial contract, in what Mr. Graylin described as an attempt to extract more fees.” Nevertheless, the firm continued to work on the investigation, the Times said.

Fortune spoke to Chris O’Rourke, CEO and co-founder of the Charleston, S.C.-based security firm Soteria, about his company’s reported involvement in the investigation. “I don’t have the ability to discuss current or previous investigations at this time,” he said. “I will say,” he added, “there is some commentary in the [Times] article we disagree with.”

LoopPay did not immediately respond to a request for comment. Fortune will update this story with additional information as it comes.

Subscribe to Data Sheet, Fortune’s daily newsletter on the business of technology.

For more on U.S.-China cybersecurity relations, watch this video.

[fortune-brightcove videoid=4503529281001]

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Photo of vegan cheese products
AITech
A Mark Cuban–backed vegan cheese company trained AI to scrutinize cardboard boxes. It’s saved $400,000
By Jake AngeloMay 1, 2026
6 hours ago
Young trade worker learning on job
SuccessHiring
Forget Big Tech: Small businesses will hire nearly 1 million grads in 2026—and some of the hottest roles are gloriously AI-proof
By Emma BurleighMay 1, 2026
7 hours ago
Andrew McAfee
SuccessCareers
MIT AI expert warns automating Gen Z entry-level jobs could backfire—and cost companies their future workforce
By Preston ForeMay 1, 2026
8 hours ago
duke
Big TechAmazon
Amazon Prime Video reaches deal with Duke Blue Devils to air 3 games per season
By The Associated PressMay 1, 2026
10 hours ago
valerie
CommentaryLayoffs
Tesla’s former HR chief: the AI layoff panic Is built on a false premise—here’s what most workers need to know
By Valerie Capers WorkmanMay 1, 2026
10 hours ago
AI
AIdisruption
Meet the Americans dismissing AI hype and using it with ingenuity: ‘The efficiencies gained out of it have been tremendous’
By Cathy Bussewitz and The Associated PressMay 1, 2026
10 hours ago

Most Popular

Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
10 hours ago
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
1 day ago
The U.S. economy is booming — just not where 50 million Americans live
Commentary
The U.S. economy is booming — just not where 50 million Americans live
By Derek KilmerMay 1, 2026
14 hours ago
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
Conferences
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
By Nick LichtenbergApril 29, 2026
2 days ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
4 days ago
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
Banking
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
By Nick LichtenbergApril 29, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.