Skip to main content

7-Eleven’s mobile payment app shut down after hackers nab $500K from customers

Keen to jump on the mobile payments bandwagon, 7-Eleven’s Japanese business recently launched 7Pay for customers looking for a quick and easy way to purchase items in-store.

But just days after the system went live at the beginning of last week, a number of customers started complaining that they were being charged for items they hadn’t bought.

The company has now suspended use of its mobile payment service while it investigates 7Pay’s security procedures, or lack thereof. In a statement released at the end of last week, 7-Eleven admitted that hackers had accessed the app and made bogus transactions affecting 900 customers to the tune of $506,000.

On Saturday, July 6, the Japan Times reported the arrest of two Chinese men who may be connected to the hack, with one of them suspected of attempted fraud after paying 730,000 yen (about $6,750) to purchase nearly 150 cartons of e-cigarette cartridges from a 7-Eleven store in Tokyo, allegedly using stolen IDs.

7Pay working using a bar code that appeared on the customer’s smartphone, with a cashier scanning it to charge the cost of the items to the customer’s linked debit or credit card.

But a report by ZDNet said the app was so poorly designed that it allowed anyone with knowledge of a customer’s email address, date of birth, and phone number to take over an account.

The hacker did this by using the data to reset an account’s password, with the reset link able to be sent to the hacker’s email address instead of the account owner’s. The hacker could then take control of the account.

The suggestion is that hackers automated the attack using information gathered in previous online security breaches targeting Japanese databases.

The alarming ease with which hackers were able to exploit 7Pay prompted the Japanese government to get involved, with the Ministry of Economy, Trade, and Industry accusing 7-Eleven of failing to properly adhere to guidelines preventing such unauthorized access. The company, which operates more than 20,000 stores in Japan, has apologized for the mishap and promised to fully reimburse those affected.

The 7Pay incident brings to mind another mobile payment breach several years ago when the now-defunct CurrentC system was targeted by hackers during its testing phase. Whether 7Pay will be resurrected with much-improved security or ends up going the same way as CurrentC remains to be seen.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
The first HMD Android phones are here, and they’re super cheap
Rear shell of HMD Vibe smartphone.

Finnish company Human Mobile Devices is renewing its journey under the HMD branding, shedding aside the Nokia naming it used to use for all of its smartphones. The first handsets to bear the HMD branding are the HMD Pulse, HMD Pulse+, HMD Pulse Pro, and the HMD Vibe. All phones share similar aesthetics, with a few splashy colors thrown in for certain trims, and target the budget segment.

The HMD Vibe, for example, serves a 6.56-inch display with an HD+ resolution and a 90Hz refresh rate. Qualcomm’s Snapdragon 680 silicon runs the show, alongside 4GB of RAM and 128GB storage. Notably, there’s a microSD card slot that supports storage expansion up to 512GB.

Read more
How to view Instagram without an account
An iPhone 15 Pro Max showing Instagram via a web browser.

Instagram is one of the largest social media platforms on the planet. Whether you want to share a family photo, what you had for lunch at your favorite cafe, or a silly video of your cat, Instagram is the place to do it.

Read more
Something odd is happening with Samsung’s two new budget phones
A person holding the Samsung Galaxy A35 and Galaxy A55.

The Samsung Galaxy A35 (left) and Galaxy A55 Andy Boxall / Digital Trends

I’ve been using the Samsung Galaxy A55 for almost two weeks and have now swapped my SIM card over to the Samsung Galaxy A35. These are the latest entries in Samsung's budget-minded Galaxy-A series. In all honestly, I can barely tell the difference between them.

Read more