• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic

2

‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion

3

Power companies are using eminent domain to seize land for data centers as 70% of Americans say not in my backyard

1

'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic

2

‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion

3

Power companies are using eminent domain to seize land for data centers as 70% of Americans say not in my backyard
TechCybersecurity

Retailers Scrambling Against Latest Credit Card-Stealing Malware

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
November 24, 2015, 6:45 PM ET
<> on November 17, 2015 in New York City.
<> on November 17, 2015 in New York City.Photograph by Spencer Platt—Getty Images
Add Fortune on Google for similar content.

Hackers are targeting U.S. retailers with a new wave of malware intended to steal credit card and debit card information from payment terminals, according to a cybersecurity firm.

News of the attacks arrive just ahead of holiday shopping season, a particularly busy time of year for the retailers, health care providers, payment card processors, and hospitality companies that may be affected.

“This is by far most the most sophisticated point of sale malware we’ve seen to date,” said Maria Noboa, technical analyst at iSight Partners, whose team discovered the difficult-to-detect malware. “They have such great in-depth understanding of operational security measures, evading detection and the mitigation techniques used,” she said about the coders’ expertise.

The malware in question involves separate modules that run close to computers’ operating systems, making them harder to analyze. These “rootkit” modules—tools that enable the hackers to remain hidden and in control—also use advanced encryption that prevents traditional anti-virus and other monitoring software from detecting them.

“We have found three right now, and we are sure there are more out there,” said Stephen Ward, marketing director at iSight, about the modules. First, there’s a “keylogger,” that records and stores keyboard strokes. Second, there’s an “uploader-downloader” that connects compromised machines with the hackers’ command and control infrastructure, or remote servers that can send and receive data or instructions to and from infected devices. And third, the iSight researchers identified a “POS scraper” that steals payment card information from the memory of retailers’ computers.

Pieces of the malware seem to have been in in development as early as 2012, according to iSight. Attacks based on the malware began targeting U.S. retailers a year later, and the assaults are likely ongoing, Noboa said.

iSight named the malware “ModPOS” after its characteristic modules. The firm said it has found no discussion of it on online crime forums, which suggests that a single professional-level hacking group is behind the scam. Although firm evidence is lacking, some indicators suggest that the malware might be Eastern European in origin.

iSight said it began notifying clients of the threat in October, and other retailers more recently in order to give them time to track down and remove the malware from their machines before the Black Friday and Cyber Monday shopping sprees.

Wendy Nather, research director at the Retail Cyber Intelligence Sharing Center, an industry group that shares cybersecurity information, told Fortune that members of the organization have been hunting for the malware on their systems since learning of it. “I don’t know if anyone has been effective in kicking it off their system, or what measures need to be taken to remove it,” she said. “It’s bigger in functionality, has more sophisticated coding, and it’s trickier about hiding,” compared to other recent [point of sale] malware attacks, she said.

Formed this year, the retail info-sharing group’s membership includes about 50 companies such as J. C. Penney (JCP), Nike (NKE), Target (TGT), and Walgreens (WAG).

Nather noted that it was interesting to see that the attackers had not changed their IP addresses—the equivalent of street addresses on the Internet—since its earliest beginnings in 2012. “That’s very unusual for malware because, generally, as soon as someone figures out and shares IP address information, the attackers have to change them and move on,” she said. “They must have felt confident enough to use the same IP addresses so long as they didn’t believe they had been discovered all this time.”

Neither iSight nor the retail group revealed which companies are victims of breaches involving the malware. “We can’t get into specifics on the victim side other than to say that the potential is millions of credit cards,” Ward said.

The recent push by banks to implement security chip-enabled credit cards and by merchants to install chip-reading terminals in stores is “not a cure-all,”Noboa said. The beefed up protections should prevent hackers from creating counterfeit credit cards, but they are no defense against fraudulent “card not present” transactions, such as occur online.

A better preventative guard against the attack would be for retailers to thoroughly encrypt their customers’ banking data within their computer systems, Noboa said.

In its 2015 Global Security Report, the cybersecurity firm Trustwave, which was acquired by the Singaporean telecommunications firm Singtel for $810 million earlier this year, found that two out of five data breaches it examined involving nearly 600 investigations were related to point of sale system compromises.

At the end of 2013, Target (TGT) notoriously suffered a massive security breach that involved as many as 40 million payment cards. Home Depot last year was hit with a breach last year that compromised as many as 56 million payment cards.

Follow Robert Hackett on Twitter at @rhhackett. Read his cybersecurity, technology, and business coverage here. And subscribe to Data Sheet, Fortune’s daily newsletter on the business of technology, where he writes a weekly column.

For more on Thanksgiving shopping, watch the video below:

 

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

LaLiga president says tech is already making the fan experience better, and it could solve football’s money problem too
AISports
LaLiga president says tech is already making the fan experience better, and it could solve football’s money problem too
By Catherina GioinoJuly 20, 2026
1 hour ago
A 13-year-old teenage boy looks at an iPhone screen displaying various social media apps.
PoliticsSocial Media
French President Macron backs effort to ban kids under 15 from social media before departing office next year
By The Associated Press and Samuel PetrequinJuly 20, 2026
2 hours ago
Photo of Hugging Face cofounder and CEO Clement Delangue.
CybersecurityAI agents
Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense
By Emily ForliniJuly 20, 2026
3 hours ago
Sumeet Agrawal is VP of Product Management (Data, AI Governance & Context Engineering for Agentic Systems) at Salesforce.
CommentaryAI agents
Salesforce VP on the leaky AI pipeline: why cheaper tokens won’t fix enterprise AI
By Sumeet AgrawalJuly 20, 2026
8 hours ago
Artificial Intelligence technology and futuristic technology transformation
C-SuiteCFO Daily
How CFOs can tell if AI is actually creating value
By Sheryl EstradaJuly 20, 2026
9 hours ago
uk
PoliticsSocial Media
France wants to ban social media for kids — but Brussels says the bill breaks EU law
By Samuel Petrequin and The Associated PressJuly 20, 2026
9 hours ago

Most Popular

'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
AI
'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
By Jason MaJuly 18, 2026
2 days ago
‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion
Success
‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion
By Sydney LakeJuly 20, 2026
8 hours ago
Power companies are using eminent domain to seize land for data centers as 70% of Americans say not in my backyard
AI
Power companies are using eminent domain to seize land for data centers as 70% of Americans say not in my backyard
By Aaron Walayat and The ConversationJuly 19, 2026
2 days ago
Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock
Success
Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock
By Sasha RogelbergJuly 20, 2026
4 hours ago
Red Lobster’s 37-year-old CEO waited tables before joining the C-suite—he says it was a crash course in managing ‘difficult people and situations’
Success
Red Lobster’s 37-year-old CEO waited tables before joining the C-suite—he says it was a crash course in managing ‘difficult people and situations’
By Preston ForeJuly 19, 2026
2 days ago
Warren Buffett says his $147 billion investing career was an accident: ‘I may be one of the 10 luckiest in the world’
Future of Work
Warren Buffett says his $147 billion investing career was an accident: ‘I may be one of the 10 luckiest in the world’
By Sarah GlodekJuly 20, 2026
15 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.