7-Eleven’s mobile payment app shut down after hackers nab $500K from customers

Keen to jump on the mobile payments bandwagon, 7-Eleven’s Japanese business recently launched 7Pay for customers looking for a quick and easy way to purchase items in-store.

But just days after the system went live at the beginning of last week, a number of customers started complaining that they were being charged for items they hadn’t bought.

Recommended Videos

The company has now suspended use of its mobile payment service while it investigates 7Pay’s security procedures, or lack thereof. In a statement released at the end of last week, 7-Eleven admitted that hackers had accessed the app and made bogus transactions affecting 900 customers to the tune of $506,000.

On Saturday, July 6, the Japan Times reported the arrest of two Chinese men who may be connected to the hack, with one of them suspected of attempted fraud after paying 730,000 yen (about $6,750) to purchase nearly 150 cartons of e-cigarette cartridges from a 7-Eleven store in Tokyo, allegedly using stolen IDs.

7Pay working using a bar code that appeared on the customer’s smartphone, with a cashier scanning it to charge the cost of the items to the customer’s linked debit or credit card.

But a report by ZDNet said the app was so poorly designed that it allowed anyone with knowledge of a customer’s email address, date of birth, and phone number to take over an account.

The hacker did this by using the data to reset an account’s password, with the reset link able to be sent to the hacker’s email address instead of the account owner’s. The hacker could then take control of the account.

The suggestion is that hackers automated the attack using information gathered in previous online security breaches targeting Japanese databases.

The alarming ease with which hackers were able to exploit 7Pay prompted the Japanese government to get involved, with the Ministry of Economy, Trade, and Industry accusing 7-Eleven of failing to properly adhere to guidelines preventing such unauthorized access. The company, which operates more than 20,000 stores in Japan, has apologized for the mishap and promised to fully reimburse those affected.

The 7Pay incident brings to mind another mobile payment breach several years ago when the now-defunct CurrentC system was targeted by hackers during its testing phase. Whether 7Pay will be resurrected with much-improved security or ends up going the same way as CurrentC remains to be seen.

Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
How one special feature changed my smartphone photos forever

I don’t usually mess around with Pro modes in smartphone camera apps much. I’m not a “pro,” so they rarely seem relevant, and the combination of an effective auto mode and a great editing platform usually means I end up with a photo I’m pleased with anyway.

But that all changed when I tried Master Mode on the OnePlus 12. Yes, it’s a Pro mode in disguise, but it has an unusual and quite specific feature set that has helped me create photos I love and furthered my own photographic style far more than most other phones I’ve used recently.
Personal photographic style

Read more
The best Android tablets in 2024: the 11 best ones you can buy

Tablets may not be the hot new thing in 2024, but they're still excellent machines for streaming movies, playing games, or getting work done on the go. And while it seems like the best iPads dominate most of the tablet market, there are still plenty of excellent Android tablet options for consideration if you don't want to be locked in Apple's walled garden.

Whether you want an ultra-premium and superpowerful option, or something more affordable and compact, the Android tablet market has something for everyone. No matter your budget or spec preferences, here are the best Android tablets you can buy in 2024.

Read more
The best Samsung Galaxy Watch in 2024: Which one should you buy?

While the openness of the Android ecosystem means there’s no shortage of options to choose in terms of smartwatches, Samsung’s Galaxy Watch family leads the pack by a wide margin.

The Galaxy Watch 6 marks the wearable’s fifth generation (there was never a Galaxy Watch 2), which means the line has had plenty of time to evolve and mature. Samsung’s decision to embrace Wear OS two years ago and expand the lineup in new directions with an adventurous “Pro” model and the return of the much-loved rotating bezel means that there’s now a Galaxy Watch for just about everyone.

Read more