Skip to main content

Samsung Pay flaw could allow hackers to intercept and decode credit card info

samsung pay update masterpass galaxy s7 edge
Jeffrey Van Camp/Digital Trends
Mobile payments may be the future. Indeed, researchers at eMarketer predict contactless payments, or transactions completed with “tap-to-pay” tech like Android Pay or Apple Pay, could grow 210 percent this year to $27.05 billion — but that doesn’t mean they’re secure. Case in point: a recently discovered bug in Samsung Pay, Korean company’s eponymous proprietary payments platform, theoretically allows hackers to intercept and decode credit card info.

At the Black Hat Security conference in Las Vegas last week, security analyst Salvador Mendoza demonstrated a flaw in Samsung Pay’s tokenization process, the string of numbers and letters the platform randomly generates to obfuscate payment details, that could allow a hacker to “guess” at a purchaser’s credit card number. Tokens could be predicted, he explained: After a specific credit or debit card is added to Samsung Pay and associated with a specific token, future tokens inexplicably become “weaker” and easier to guess.

Central to the flaw’s execution is Samsung’s magnetic secure transmission technology, a feature on the company’s newest flagship Galaxy phones which lets users pay at legacy registers. At transaction time, a specialized chip within the phone emits a signal which mimics the magnetic strip on a credit card. The terminal processes a physical swipe as usual — an undoubted convenience at retailers contactless-compatible payments terminals. But it also provides a means to collect the initial, “seed” token from which the others can be deciphered, Mendoza said.

swipe-1-jpg
Image used with permission by copyright holder

Obtaining the token isn’t necessarily easy — it requires special hardware that’s capable of spoofing a magnetic payments terminal, first of all, and furthermore access a victim’s phone. But it’s far from impossible. Mendoza designed an open source prototype that’s small enough to transport — during the Black Hat demonstration, he strapped it to his arm — and perhaps more worryingly, easily concealed within off-the-shelf terminal hardware. The skimming process can be automated, even — Mendoza’s mock-up forwarded intercepted tokens to an e-mail inbox.

Once the initial payment token is intercepted, a user’s future tokens can be easily guessed, Mendoza said. He sent a generated token to a friend in Mexico who was able to purchase an item from a vending machine with magnetic spoofing hardware — despite the fact that Samsung Pay isn’t even available in Mexico.

Nothing precludes “every credit card, debit card, or prepaid card from any affiliated bank” from susceptibility, Mendoza said — since Samsung Pay pay generates tokens indiscriminately, one is no less predictable than another. But he offered some consolation: gift cards are safe. That’s because Samsung Pay generates a bar code for gift cards rather than a transmittable token.

swipe-2
Image used with permission by copyright holder

Last week, Samsung issued a statement which characterized Mendoza’s research as “inaccurate” and misleading. “Samsung Pay is built with the most advanced security features, assuring all payment credentials are encrypted and kept safe, coupled with the Samsung Knox security platform,” a spokesperson said. “If at any time there is a potential vulnerability, we will act promptly to investigate and resolve the issue.”

The company offered a more detailed rebuttal on Monday:

We are aware of a recent and inaccurate report regarding the security of Samsung Pay. We would like to clarify that Samsung Pay is built with highly secure technology and is the most widely accepted mobile payment solution available today.

Each Samsung Pay transaction uses a digital token to replace a card number. The encrypted token combined with certificate information goes through multiple security layers and can be used only once to make a payment. Samsung Pay is designed so that merchants and retailers cannot see or store the actual card data, and our customers are notified with each transaction. Multiple layers of security from Samsung Pay and our partners are in place to detect threats to security.

Security is our number one priority at Samsung — and always will be. We are committed to securing and protecting user data.

Samsung Pay is off to an amazing start and we are proud to offer the only mobile payment option that works almost anywhere you can swipe or tap a card today.

We’ve reached out to the company for clarification.

Security experts have warned that mobile payments security, broadly speaking, isn’t as ironclad as advertised. A survey of over 900 cybersecurity professionals conducted as part of ISACA’s 2015 Mobile Payment Security Study found that nearly half, or 47 percent, believe that mobile payments carried significant risks, and that most didn’t have faith in current mechanisms to prevent hacks — more than 87 percent said they expected a “surge” in mobile payments data breaches in the next year.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Today’s Galaxy Tab S9 deal: $100 off and free Buds 2 Pro
Samsung Galaxy Tab s9 back and front visible

If you've had your eyes on the Samsung Galaxy Tab S9 for a while, now's the perfect time to buy the tablet. The 8GB of RAM and 128GB SSD model is available from Samsung tablet deals for $700, following a $100 discount on its original price of $800, and you'll get the Samsung Galaxy Buds 2 Pro, worth $230, for free. That's a total of $330 in savings if you proceed with the purchase right away, so what are you waiting for? Complete the transaction right now, because the bargain may be gone as soon as tomorrow.

Why you should buy the Samsung Galaxy Tab S9
The Samsung Galaxy Tab S9 FE Plus and the Samsung Galaxy Tab S9 Ultra are featured in our roundup of the best tablets, but don't ignore the Samsung Galaxy Tab S9. The base model of the tablet is an excellent tool for all-around usage with its Qualcomm Snapdragon 8 Gen 2 processor and 8GB of RAM, which combine for dependable performance in handling everyday functions. The device comes with internal storage of 128GB, but if that's not enough for you, there's an option for extra space of up to 1TB by inserting a microSD card.

Read more
Best Apple deals: Save on AirPods, Apple Watch, iPad, MacBook
Apple MacBook Air M1 open, on a table.

Apple has been a big player in the tech space for a long time, and it has pioneered some of the technology we use today, such as best wireless earbuds and the best smartwatches. If that wasn't enough, it even makes some of the best best laptops and best tablets on the market, so pretty much whatever tech you're looking for, Apple has an excellent version of it. Not only that, but Apple's ecosystem is also easily one of the best available, with only Samsung really competing in that space, and if you're already in the Apple ecosystem, then it makes sense to continue buying stuff from Apple.

Of course, Apple tech can be quite pricey, which is why we've gone out and searched through various big retailers to find you some of the best deals we can find. That includes everything from the MacBook deals, AirPods deals, Apple TV deals and Apple Watch deals to the AirTag, so hopefully, you can find the perfect deal that fits your needs and budget.
Apple AirTag (4-Pack) -- $80, was $99

Read more
This is the iPhone concept of my dreams
iPhone concept mimicking iPad Pro desgn.

It’s an odd day to be talking about iPhone design. Yesterday, Apple delivered what can be called the pinnacle of tablet aesthetics with the 2024 iPad Pro, which is even slimmer than the iPod Nano. Today, Bloomberg reports that Duncan Kerr -- a design executive from the legendary Jony Ive group and was a key figure behind the iPhone, iPad, and Mac products since 1999 -- is leaving the company.

It’s a great loss for Apple and disheartening news for iPhone enthusiasts. Apple almost seems obsessed with the design language it introduced with the iPhone 11 series. And if recent leaks are any indication, we are going back to the iPhone X days with the non-Pro iPhone 16 models later this year.

Read more