Every time a customer taps, swipes, or inserts a card at a checkout counter, sensitive payment data flows through a point of sale (POS) system. That data is exactly what criminals want. POS systems sit at the meeting point of money, technology, and physical access, which makes them one of the most attractive targets in all of retail. Threats arrive from two very different directions: outsiders breaking in over the network, and insiders abusing the access they already have. Understanding both, and the specific tricks attackers use on the terminals themselves, is the first step toward keeping a store and its customers safe.
Table of Contents
- Internal versus external threats to POS security
- The technical controls every retailer needs
- Terminal tampering attacks: stolen and modified POS devices
- Why unattended terminals are so vulnerable
- Skimming attack examples: fake errors and software failures
- Simple steps to reduce skimming risk
- Keep an inventory of every device
- Check that serial numbers match
- Inspect for physical signs of tampering
- Remove suspicious devices and train your team
- Building a culture of POS security
Internal versus external threats to POS security
POS security threats fall into two broad categories, and a serious retailer has to plan for both. External threats come from outside the organisation. Hackers often enter through an unsecured internet or wireless connection, intercepting payment data as it travels or planting malware that quietly copies cardholder information from the system’s memory. A common pattern is for attackers to break in through a weaker, less-protected device on the network and then move sideways toward the payment systems, where the valuable data lives.
Internal threats are equally dangerous and often overlooked. Employees with legitimate access to the POS system and customer data can cause a breach, whether deliberately or by accident. A staff member tricked by a phishing email, a disgruntled worker, or simply a careless click can open the door just as wide as an external hacker. Because insiders already operate inside the trusted environment, their actions can be far harder to detect than an outside intrusion.
This is why one-dimensional defences fail. A firewall alone does nothing against a malicious employee, and background checks alone do nothing against a remote hacker. Retailers need layered, technical controls to cover both fronts.
The technical controls every retailer needs
Three technical defences form the backbone of POS protection. Data traffic monitoring means continuously watching the flow of information across the POS environment to spot unusual activity, such as failed login attempts or unexpected data leaving the network. Keeping login audits, tracking user behaviour, and reviewing access logs all help catch both insiders and intruders early.
Encryption scrambles cardholder data so that even if it is intercepted, it is unreadable without the decryption key. Tokenization goes a step further by replacing the actual card number with a randomly generated stand-in value called a token, which is useless to anyone who steals it. In India this is not just good practice but a regulatory requirement. Under Reserve Bank of India rules effective from 30 September 2022, merchants are prohibited from storing customers’ actual card details; only card issuers and networks may retain them. Tokenization removes much of the compliance burden from merchants while keeping transactions secure, because there is simply no raw card data left for a thief to grab.
These controls are reinforced by the global Payment Card Industry Data Security Standard (PCI DSS), which sets a baseline covering encryption, access controls, and protecting physical terminals against tampering. Any business that accepts card payments is expected to comply, and failure to do so invites both breaches and penalties.
Terminal tampering attacks: stolen and modified POS devices
Not every attack happens over the internet. Some of the most damaging ones are physical, and they exploit a weakness most stores never think about: the terminal itself can be stolen, altered, and returned without anyone noticing.
In a classic terminal tampering attack, thieves physically remove POS terminals from unattended areas. Slow business hours are the favourite window, because there are fewer staff and customers around to notice. Organised crime groups then modify the stolen terminals by inserting skimming devices, the small hidden components that secretly copy card data and PINs during a normal transaction. The patent literature describing these attacks notes that skimmers are typically affixed to read the magnetic stripe, while keypad overlays record the PIN as the customer types it.
The genuinely clever and dangerous part comes next. The criminals do not necessarily return the tampered terminal to the store they stole it from. Instead they reintroduce modified units back into service at other locations. Unsuspecting staff then repair, accept, and redeploy these compromised devices, putting a data-harvesting tool right back on the counter where customers will use it.
Why unattended terminals are so vulnerable
A Visa security alert documented how perpetrators work in teams: one person installs the skimming device on the terminal while another creates a barrier or distraction so no one observes it. Some have faked a medical emergency or caused a commotion to pull staff attention away from the counter. The same alert notes that these criminals are mobile, targeting multiple stores across a geographic area before moving on, and that they prefer terminals that are often left unattended, such as those near self-checkout lanes, deli counters, and stand-alone kiosks. The lesson is direct: any terminal that sits unwatched, even for a few minutes, is a target.
Skimming attack examples: fake errors and software failures
Some of the most effective skimming attacks succeed not through brute force but through social engineering of the store’s own staff. The attacker relies on a predictable human response to a malfunctioning machine.
In one documented approach, the modified terminal was made to generate an error after skimming a card, so the device appeared to have a simple card-reading or cable problem. Staff, seeing what looked like an ordinary hardware glitch, treated it as routine. In another approach, the terminal was made to look like it had a software failure that required a download to fix. In both cases the appearance of a benign technical fault was the disguise. Staff troubleshooting the “broken” unit unknowingly returned the tampered terminal to service, with the skimming hardware still inside and fully active.
This is what makes these attacks so insidious. The compromised device behaves almost normally, and the small irregularities it shows are designed to look like the everyday faults employees encounter all the time. Without specific training, there is no reason for a staff member to suspect that an error message is actually evidence of a crime in progress.
Simple steps to reduce skimming risk
The good news is that the defences against physical tampering are practical and inexpensive. They depend more on routine and vigilance than on expensive technology. A handful of disciplined habits dramatically reduce the risk.
Keep an inventory of every device
Maintain a complete list of all POS equipment, recorded by serial number. PCI DSS explicitly calls for merchants to maintain a device inventory log and conduct periodic inspections, recording the model, serial number, and location of each terminal. An up-to-date inventory is what lets you notice when a device has been swapped for a counterfeit, because a substituted unit will not match your records.
Check that serial numbers match
Most terminals carry a sticker on the underside showing the serial number, and the same number can usually be displayed electronically on screen. The PCI Security Standards Council advises that a legitimate terminal’s sticker serial number should match the electronic one – if they differ, there may be a skimmer inside. Running a finger along the label also helps detect a skimming device hidden beneath it. A mismatch is one of the clearest signs that a device has been tampered with or replaced.
Inspect for physical signs of tampering
Visually examine each terminal for anything out of place. Look for missing screws, holes in the casing, extra wires, unfamiliar labels, or anything inserted into the card reader, ports, or keypad. Security stickers placed over screw holes and seams act as indicators: if one is broken or missing, the case may have been opened. Unusual cables are another red flag, since attackers sometimes swap a standard cable for a modified one that transmits stolen data.
Remove suspicious devices and train your team
If a terminal shows any sign of tampering, take it out of service immediately and do not process payments on it. If there is evidence of tampering – broken gaskets, screwless parts, different cables – the device should not be used, and daily inspections should be part of normal routine. Where a terminal displays the word “TAMPER” on screen, Adyen’s guidance is to stop using it at once and contact support, since this is the device itself reporting that it has been interfered with.
None of this works without people. Employees are the first line of defence, so they must be trained to recognise the signs of tampering and to understand that a strange error message or an unexpected “software update” prompt could be the symptom of an attack rather than an ordinary fault. A staff member who knows what to look for, and who feels empowered to pull a suspicious device off the counter, is worth more than any single piece of security software.
Building a culture of POS security
Technical controls and physical inspections only deliver their full value when they become routine rather than occasional. The strongest retailers combine network defences, encryption and tokenization, and disciplined daily terminal checks into a single, consistent practice. They also pay attention to who has access, because the internal threat is real, and they screen and supervise the people who handle payment hardware. Security at the point of sale is not a product you buy once; it is a habit you maintain every day the store is open.
What do you think? If you ran a busy store, how would you keep daily terminal inspections from being forgotten during rush hours when staff are stretched thin? And which threat would worry you more – an outside hacker you cannot see, or a trusted insider who already holds the keys?
References
- https://www.shopify.com/retail/pos-security
- https://pcsolcorp.com/how-to-protect-your-retail-pos-system-security-tools-worth-the-investment/
- https://www.vikingcloud.com/blog/pci-dss-compliance-guide
- https://www.hdfcbank.com/personal/resources/learning-centre/Pay/what-are-the-rbi-guidelines-on-tokenisation-in-india
- https://jupiter.money/glossary/card-tokenization/
- https://watchdogsecurity.io/cybersecure-canada/pci-dss-compliance-for-pos-systems
- https://image-ppubs.uspto.gov/dirsearch-public/print/downloadPdf/11645427
- https://usa.visa.com/dam/VCOM/regional/na/us/common-assets/documents/visa-security-alert-pin-pad-skimming.pdf
- https://www.cuny.edu/wp-content/uploads/sites/4/page-assets/about/administration/offices/budget-and-finance/services/payment-card-industry-compliance/CUNY-Device-Inspection-Guidelines-and-Checklist.pdf
- https://blog.pcisecuritystandards.org/whos-checking-your-point-of-sale-pos-system-for-skimming
- https://docs.adyen.com/point-of-sale/managing-terminals/security-inspection
- https://pcidssguide.com/point-of-sale-pos-security-checklist/
Leave a Reply