{"id":4162,"date":"2016-08-12T08:57:42","date_gmt":"2016-08-12T03:27:42","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=4162"},"modified":"2016-08-12T08:57:42","modified_gmt":"2016-08-12T03:27:42","slug":"data-breach-oracles-micros-payment-systems-hacked","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/data-breach-oracles-micros-payment-systems-hacked\/","title":{"rendered":"Data Breach \u2014 Oracle&#8217;s Micros Payment Systems Hacked"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/ift.tt\/2aWn4vW\" title=\"Data Breach \u2014 Oracle's Micros Payment Systems Hacked\"><\/p>\n<div>\n<div dir=\"ltr\">\n<p>\nThe risks associated with data breaches continue to grow, impacting a variety of industries, tech firms, and social networking platforms. In the past few months, over 1 Billion credentials were dumped online as a result of mega breaches in popular social networks.\n<\/p>\n<p>\nNow, Oracle is the latest in the list.\n<\/p>\n<p>\nOracle has confirmed that its <\/p>\n<p><b>MICROS<\/b><\/p>\n<p> division \u2013 which is one of the world&#8217;s top three point-of-sale (POS) services the company acquired in 2014 \u2013 has suffered a security breach.\n<\/p>\n<p>\nHackers had infected hundreds of computers at Oracle&#8217;s point-of-sale division, infiltrated the support portal used by customers, and potentially accessed sales registers all over the world.\n<\/p>\n<p>\nThe software giant came to know about the data breach after its staff discovered malicious code on the MICROS customer support portal and certain legacy MICROS systems. Hackers likely installed malware on the troubleshooting portal in order to capture customers&#8217; credentials as they logged in.\n<\/p>\n<p>\nThese usernames and passwords can then be used to access their accounts and remotely control their MICROS point-of-sales terminals.\n<\/p>\n<p>\nIn a brief letter sent to MICROS customers, Oracle told businesses to change their MICROS account passwords for the MICROS online support site \u2013 particularly passwords that are used by MICROS staff to control on-site payment terminals remotely.\n<\/p>\n<blockquote class=\"tr_bq\"><p>\n&#8220;Oracle Security has detected and addressed malicious code in certain legacy MICROS systems,&#8221; said the company. &#8220;Oracle&#8217;s Corporate network and other cloud and service offerings were not impacted by this code.&#8221;\u00a0<\/p><\/blockquote>\n<blockquote class=\"tr_bq\"><p>\n&#8220;Payment card data is encrypted both at rest and in transit in the MICROS hosted environment\u2026 Consistent with standard security remediation protocols, Oracle [requires] MICROS customers to change the passwords for all MICROS accounts.&#8221;<\/p><\/blockquote>\n<p>\nCiting unknown sources, security news site KrebsOnSecurity, <\/p>\n<p><a href=\"https:\/\/ift.tt\/2b8Bpa6\" rel=\"nofollow\" target=\"_blank\">reported<\/a><\/p>\n<p> that the attack possibly came from a Russian crime gang, dubbed <\/p>\n<p><b>Carbanak Gang<\/b><\/p>\n<p>, that has been accused of stealing more than $1 Billion from banks and retailer stores in past hacks.<\/p>\n<p>\nThe scope of the data breach is still unknown, but anonymous sources familiar with the breach have told Krebs that the hack may have affected up to 700 systems.\n<\/p>\n<p>\nSince customers payment data is encrypted both at rest and in transit, Oracle said that this information is not at risk.\n<\/p>\n<p>\nOracle acquired MICROS in 2014 in a $5 Billion acquisition deal. Currently, MICROS devices are deployed at over 330,000 point-of-sale terminals (or cash registers) at food and beverage outlets, retail stores, and hotels across 180 countries.\n<\/p>\n<p>\nThe software giant is still investigating the security breach at its payment terminal division.\n<\/p>\n<p>\nOver the past few years, the security breach has hit POS terminals \u2013 or &#8220;cash registers&#8221; \u2013 operated by a large number of retailers, food chains, hotels, and other types of merchants. Two of the best-known victims to be hit by POS malware are <\/p>\n<p><a href=\"https:\/\/ift.tt\/1dC6DkZ\" target=\"_blank\">Target<\/a><\/p>\n<p> and <\/p>\n<p><a href=\"https:\/\/ift.tt\/1AUjxBD\" target=\"_blank\">Home Depot<\/a><\/p>\n<p>.\n<\/p>\n<p>\nPOS terminals have emerged as the favorite target for cybercriminal gangs because when it comes to the cheap and easy way to siphon the vast number of payment cards, breaching a single retailer&#8217;s internal network could allow criminals to collect Millions of valid payment card numbers in a relatively short amount of time.<\/p>\n<\/div>\n<\/div>\n<p>via https:\/\/ift.tt\/2bboGDE<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The risks associated with data breaches continue to grow, impacting a variety of industries, tech firms, and social networking platforms. In the past few months, over 1 Billion credentials were dumped online as a result of mega breaches in popular social networks. Now, Oracle is the latest in the list. Oracle has confirmed that its &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/data-breach-oracles-micros-payment-systems-hacked\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Data Breach \u2014 Oracle&#8217;s Micros Payment Systems Hacked&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12],"tags":[],"class_list":["post-4162","post","type-post","status-publish","format-standard","hentry","category-itsec"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-158","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=4162"}],"version-history":[{"count":1,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4162\/revisions"}],"predecessor-version":[{"id":4163,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4162\/revisions\/4163"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=4162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=4162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=4162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}