POS firm says hackers planted malware on customer networks

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Nearly 140 bars, restaurants, and coffee shops all over the US have had POS systems infected with malware.
North Country Business Products (NCBP), a Minnesota-based provider of point-of-sale (POS) products, announced a security breach last week. The company said hackers compromised its IT system and later planted POS malware on the network of some of its customers.
The breach occurred on January 3, 2019, according to NCBP. The company said it detected suspicious activity on its network on the second day and started an investigation with the help of a third-party forensic investigator.

The investigation confirmed the breach on January 30, but according to NCBP, the attacker also appears to have detected investigators probing around, and ceased all activity on January 24.
NCBP has now published a list of 139 locations that the attacker compromised and deployed POS malware on their POS networks. All are either bars, coffee shops, or restaurants, with some being standalone businesses, while others are franchises located in various hotel chains.
...

...

NCBP is offering information on its website's frontpage for potentially affected customers. [Please be advised that the list of locations where the malware was active contains 137 entries on the NCBP website. For the full 139 entries, please consult this document here.]

NCBP POS systems are installed at over 6,500 locations, meaning the breach impacted only 2 percent of the POS firm's customer base.
...
...
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top