Skip to main content

You can break into almost any retail store’s credit card reader with 2 passwords

credit card readers password problems cashier 1
Canadian Couponing
It’s common knowledge that point-of-sale machines aren’t exactly the most secure pieces of technology in the world — you need only look at last year’s pilfering of Home Depot, Target, Neiman Marcus, Michael’s customer data for evidence of that — but the reality may be worse than previously thought. Researchers at cybersecurity firm Trustwave discovered that a vast majority of retailers fail to change the default password on their credit card readers. It’s usually 166816 or Z66816.

The researchers examined machines at more than 120 clothing, electronics, and local stores. The default password in many instances granted administrative access to the machines, Trustwave executive Charles Henderson explained at last week’s RSA security last week in San Francisco. Worst case scenario, that could enable any ruffian with the know-how to scrape payment data like credit card numbers and names.

A majority of the vulnerable terminals are manufactured by Verifone, but the company’s not necessarily the one to blame. “No one is changing the password when they set this up for the first time; everybody thinks the security of their point-of-sale is someone else’s responsibility,” Henderson told CNN Money. “We’re making it pretty easy for criminals.”

It’d be risky to try at a crowded outlet — the passwords are just lengthy enough that entering them would probably make you the target of suspicion — but the real potential for hacking arises from unsecured systems. Speaking to Digital Munition, Henderson described an instance  in which an employee inadvertently downloaded keylogging software onto a retail PoS system while attempting to install a pirated video game.

Verifone doesn’t believe there’s too much cause for concern. The passwords on new payment terminals expire periodically, a spokesperson said, and the company “hasn’t witness[ed] any attacks on the security of terminals based on default passwords.” All the same, it said retailers are “strongly advised to change the default password.”

You’d think that’d be common sense.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
The camera on this Android phone is confusing, but I love it
The back of the Tecno Camon 30 Premier.

I’m all for a lot of detail, and love to hear about the new technology that’s inside a smartphone I’m about to test, but when I have to search for an explanation of what something means, it’s not a good start. The Tecno Camon 30 Premier suffers from this problem, as it has a lot of cool camera tech that is explained in a mystifying way.

So, I thought the best thing to do was to just ignore the tech speak and find out if it takes great photos the old-fashioned way.
What's the problem?

Read more
The 5 best phones with IR blasters in 2024
The OnePlus 12's camera module.

IR blasters used to be a common component in smartphones, with big products from Samsung, OnePlus, and TCL giving users access to the cool gadget. Phones equipped with IR blasters could be used as a universal remote for your other electronics, making it easy to control your gear without the need for their default controller (which might be clunky and unintuitive to use).

Fast forward today, and attempting to find a smartphone with an IR blaster is shockingly difficult. What was once common technology is now relegated to just a handful of smartphones. You won't find any iPhones or Galaxy phones with IR blasters, but that doesn't mean you have to settle for a poorly reviewed smartphone if you're interested in the tech. You will, however, probably need to settle for either OnePlus or Xiaomi, as they're the two key players still churning out powerful smartphones equipped with IR blasters.

Read more
Why you should buy the iPhone 15 Pro instead of the iPhone 15 Pro Max
Natural Titanium iPhone 15 Pro with Chopper and BD-1 droids around it.

Apple releases multiple iPhones every year, offering folks choice in terms of size and features. In 2024, the iPhone 15 lineup includes four distinct models.

The regular iPhone 15 and iPhone 15 Plus are great for those who don’t need a telephoto lens and don’t care about the Action button or the 1TB of storage. But anyone who wants a more “pro” experience has the iPhone 15 Pro and iPhone 15 Pro Max.

Read more