• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there

As Windows XP retirement nears, businesses weigh upgrade risks

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
March 31, 2014, 2:15 PM ET

FORTUNE — After April 8th, 2014, Microsoft (MSFT) will end support, including automatic security patches, for its 13-year-old Windows XP operating system. This may sound like an inconvenience primarily for government agencies and aging uncles, but another major set of Windows XP users are the automated teller machines and credit card sales systems that handle billions of dollars of transactions daily.

While major retailers and banks are likely to be well-prepared for the end of XP, financial systems based on the software are also in the hands of a far-reaching hodgepodge of independent ATM operators and small businesses. Despite ample warning, industry analysts and insiders agree that high cost and inconvenience will keep plenty of these smaller players running outdated software for many months to come — with serious implications for the security of their systems.

Jerry Nevins, co-owner of the Kansas City cocktail bar Snow & Co., is close to the dilemma. Snow & Co. bought a point of sale system less than a year ago from the payments servicer Micros — only to be told within a few months of the need for an upgrade to Windows 7, at a cost of $1,700 for the single-store system. Luckily, Snow & Co. was still under a service agreement, so its upgrade was free. But as Nevins puts it, “If you’re a small business, an unexpected $1,700 might be like, eh, I’ll go ahead and take my chances.” Moreover, Nevins describes a “huge line” of Micros customers waiting for an upgrade. He’s crossing his fingers that Snow & Co. will be upgraded before the April 8 deadline.

MORE: Video demos: Microsoft’s Office running on Apple’s iPad

Costs to retail credit card processors will vary widely, says John Berkeley of Mercury Payment Systems. “If you have the right hardware you can just upgrade the OS, but for some merchants upgrading from XP to Windows 7 can mean all new hardware,” likely costing much more than that $1,700.

The challenges of upgrading become even bigger in the case of ATMs. ATM manufacturers are offering software upgrades for machines still based on XP — though some of those have been available for less than a month. But the cost to upgrade can be staggering.

According to Jay Weber, vice president in charge of North American debit and ATM systems for FIS Global, “An ATM machine purchased in the last five years … would only need a software upgrade of $4,000 to 5,000 per machine.” That software cost is so high in part because much specialized software written for Windows XP can’t be easily ported to a new operating system. But ATMs 10 years old or more would need to be completely replaced, and Weber says that new high-end ATMs can cost at least $50,000 to $60,000 per device.

ATM operators and business owners are largely being left to decide on their own whether to upgrade or not, says Weber. “Organizations are trying to look at the investment of the upgrade and weight it against their perceived risk” — and many seem to be ready to take their chances. “[April 9th] is going to come and go, and there are going to be some merchants who haven’t done it yet,” says Berkeley. Weber speculates that “it’s going to be a trickle approach, a slower ramp-up,” with many systems going without an upgrade — and remaining officially insecure — through the end of 2014.

MORE: Can Microsoft make enterprise search better?

This hesitancy may be worsened because operators are getting mixed messages about their risk. The Payments Card Industry Security Standards Council has issued public warnings about the need for retailers to upgrade their point of sale systems, but their current set of standards, which are used to determine eligibility to operate on credit card networks, do not require it. And Weber himself seems sanguine: “The risk is hard to quantify. There’s a lot of technology in place in the marketplace to help mitigate the risk,” such as the “fairly closed telecom environment” that most payment systems operate on.

But Bogdan Botezatu, senior e-threat analyst for the anti-malware software company Bitdefender, couldn’t disagree more. He talks about the issue with the barely suppressed terror of a father watching his teenage son drive solo for the first time. “They’re not panicky,” he says, “and actually that makes me panicky.”

Botezatu, who haunts underground hacking forums to keep an eye on looming security threats, claims that hackers are gearing up to raid suddenly insecure XP machines the minute Microsoft support ends. “When an operating system is announced as reaching its end of life, [hackers] are frantically looking for exploits, because then they can use it indefinitely,” he says. “It’s the holy grail of malware.”

To take fullest advantage of the situation, black-market vendors selling new XP exploits have been stockpiling them, waiting to release them until after Microsoft is no longer monitoring and repairing security flaws. Though third-party security firms will continue to update anti-malware programs for XP, users not running or updating such software could be permanently vulnerable to an ever-growing set of exploits. Mercury Payment Systems’ John Berkeley confirms that “If a hacker discovers [a vulnerability] a month or two after the end of [XP support], they have more time to exploit that.”

MORE: Microsoft culture must change, chairman says

These exploits could range from stealing credit card information from small vendors to even more dramatic forms of theft, many of them easily circumventing external security measures such as the semi-closed payments network. Botezatu says there have been reports of an ATM exploit through a mobile phone connected through an ATM’s card reader. He also cites a legendary stunt by the security expert Barnaby Jack at the Black Hat security conference in 2010, where he demonstrated a “Jackpotting” hack that easily emptied an XP-based ATM machine. According to Botezatu, Jack, who died in 2013, never revealed the nature of this exploit, meaning that it could remain an unpatched vulnerability in XP-based machines.

Most troubling of all, Botezatu predicts that unsecured XP machines of all kinds will be compromised by hackers to form new botnets. This kind of system, in which hacked systems’ processors are put to new tasks unbeknownst to their owners, can be used for everything from massive Denial of Service attacks to mining cryptocurrency, and would add substantially to the insecurity of the Internet as a whole. “I see a lot of trouble,” Botezatu warns.

Whether April 9th brings a plague of cash-spewing ATMs, zombie PCs, and thieving credit-card readers remains to be seen. But Botezatu sounds exasperated that he even has to consider these scenarios. “It’s an operating system that was released 13 years ago. Everyone should have started migrating two or three years ago” to avoid the mad rush and risks that come with the end of support. He hopes, at least, that this episode will motivate today’s users to think about the future.

“This is going to happen soon with other operating systems,” Botezatu says. “You should start upgrading from Windows 7 now.”

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
Commentarydata sovereignty
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
By Leonard LimJune 10, 2026
2 hours ago
The curse of Trump watching sports in person: the home team seems to always lose
Arts & EntertainmentDonald Trump
The curse of Trump watching sports in person: the home team seems to always lose
By The Associated Press and Will WeissertJune 10, 2026
2 hours ago
Microsoft co-founder Bill Gates (C) arrives for a closed-door interview with the House Oversight Committee on Capitol Hill in Washington, DC, on June 10, 2026.
LawBill Gates
Gates testifies on Epstein: previous Fortune investigation reveals payments to his ex-girlfriend, $1M Microsoft deal
By Eva Roytburg, Joey Cappelletti, Hannah Schoenbaum and The Associated PressJune 10, 2026
3 hours ago
How the World Cup is a high-stakes stage for Big Tech’s AI push
NewslettersCIO Intelligence
How the World Cup is a high-stakes stage for Big Tech’s AI push
By John KellJune 10, 2026
4 hours ago
‘I love the inflation’: Trump is ‘not concerned’ about inflation hitting 4% for the first time since 2023. ‘The numbers were great’
EconomyDonald Trump
‘I love the inflation’: Trump is ‘not concerned’ about inflation hitting 4% for the first time since 2023. ‘The numbers were great’
By The Associated Press and Christopher RugaberJune 10, 2026
4 hours ago
A man guides a ship in the water.
EnergyOil
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
By Sasha RogelbergJune 10, 2026
4 hours ago

Most Popular

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
2 days ago
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
Economy
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
By Nick LichtenbergJune 9, 2026
1 day ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
2 days ago
Current price of oil as of June 9, 2026
Personal Finance
Current price of oil as of June 9, 2026
By Joseph HostetlerJune 9, 2026
1 day ago
Wall Street dumped nearly $1 trillion in tech stocks by midday—then clawed it back and bought peanut butter and paint
Investing
Wall Street dumped nearly $1 trillion in tech stocks by midday—then clawed it back and bought peanut butter and paint
By Eva RoytburgJune 9, 2026
1 day ago
Current price of silver as of Tuesday, June 9, 2026
Personal Finance
Current price of silver as of Tuesday, June 9, 2026
By Joseph HostetlerJune 9, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.