About 18 years ago, a business called me because customers’ card information was being stolen.
No one had found a card skimmer. There was also no proof that an employee was involved.
I needed to find another way the card data could be leaving the business.
This is an old story from early in my IT career. Payment systems have changed a lot since then. I have also changed details about the business, software, and network to protect the client.
I checked the network
I used digital forensic skills to study the data moving in and out of the business.
I also used the same thinking I would use during a security test. I looked for a door into the system that someone outside the business might be able to reach.
The payment system gave me the first clue.
A connection stayed open overnight
The business used a phone or early DSL connection to send batches of card payments.
The connection should have closed after each batch. A software problem left it open overnight.
That gave someone more time to reach the system.
The network traffic showed that card information was exposed through the open connection. I also found signs that someone was taking the data.
I could not identify the person or find their location. The evidence showed how the data was leaving, but it did not show who was taking it.
We closed the opening
We fixed the software problem so the connection closed after each payment batch.
Then we watched what happened.
The reports of stolen card information stopped.
Here is what the evidence showed:
- The connection stayed open too long.
- Card information was exposed.
- The traffic showed signs that the data was being taken.
- The theft stopped after we closed the connection.
The open connection was the likely path into the system.
The hacking mindset helped
Hacking skills are often about finding ways into a system that its owners did not know were there.
I looked at what could be reached, when it was open, and what data moved through it. That helped me find the connection that stayed open overnight.
Modern payment systems work differently, so this story is not current payment-security advice.
The main lesson still holds. When the common answers do not explain the evidence, look at what the system is doing. Find the opening, close it, and make sure the problem stops.