How Customer Payment can be affected by Weak Cyber Security
The incident of the data breach of Home Depot – Australia’s well-known company to get home improvement tools for the ‘DIY’ project, is just one of the many reported incidences of cyber attacks worldwide.
When a reputable company is attacked by hackers or cyber criminals, the company not only loses a handsome sum of money, as Home Depot lost $179 million, but also ends up paying money to the entities and financial institutions that indirectly get affected with such cyber attacks, which are, the real victims of a weak cyber security system.
Related: Five Companies Who Have Lost thousands of Customer Payments
The Repercussions of a Cyber Attack
Whenever you read about a multimillion-dollar theft in a bank, or a million passwords leaked on the web or a scam milking billions from vulnerable users - what you are reading is a reflection of a weak cyber security system. In short, a failed attempt of protecting processes, systems or data that eventually enabled exploitation.
Sometimes, the repercussions of this failed attempt of managing a strong cyber security network can be quite an embarrassment for companies or even individuals. However, at other times, this failure may lead to significant operational and financial harm. To think the worst, even a loss of life can occur.
So what really stimulates these cyber attacks and what do these attackers aim to achieve with that?
Cyber attacks come in a variety of methods, ranging from blackmail, attacks on websites, theft, manipulation, extortion or even destruction. The tools that are usually used to carry out the intermittent attacks vary and include ransom ware, malware, social engineering, spyware and even alterations to devices, for instance, ATM skimmers.
If an organisation or financial institution such as a bank does not support a strong cyber security system or there is no check over its functionality to adapt the changing mechanism of cyber attacks, this becomes a major concern with regards to customer data protection.
Cyber Attacks Affecting Customer Payments:
Criminals have successfully discovered the ways to exploit market and financial systems that are associated with the internet such as ACH – Automated Clearing House. Although cybercriminals are not always after money but a majority of these criminal attempts are for financial gains, affecting the customer payments eventually.
By attacking the system user instead of the system itself, the cyber attackers earn direct excess to a various credit card or bank accounts including other financial systems that easily allow them to make unauthorised transactions.
Online Payment Systems Appeal to Attackers:
The system of making online payments is highly appealing for cyber attackers. Having a designed system to accept customer payments is a critically important aspect of online businesses and also the last step of a customer’s purchase journey.
The Technique Used:
To affect customer payment, one of the reported incidents used a technique in which hackers recruited many volunteers for help and all of them installed special software for an attack on their systems that collectively become a large botnet.
The installed software was designed to carry out a large Distributed Denial of Service–DDoS—attack on a company’s network. Using a chat platform, instructions were sent to the computers in botnet to initiate the attack on the network of the company. Due to this large scale attack and involvement of many people, the customer payment system was quickly interrupted and remained inaccessible for almost 10 hours.
In line with the above example, whenever an online payment system is attacked by cyber criminals, it creates a huge financial impact on many businesses. It halts the business operations for an unknown period of time, which is why companies are now outsourcing their online payment system to ensure strong cyber security.
Credit Card information: an attraction to Cyber Criminals
While many businesses offer the option of saving credit card information to make the shopping experience more convenient, it gives an excellent platform to cyber attackers to play around with the information. Cyber attackers usually attack payment processing vendors because it has a greater chance for a big score.
In the brick and mortar world, there are a variety of techniques to charge a credit card at POS terminals or ATMs. In addition, there are some specifically designed attack vectors to target vendors of online payment processing directly.
And the same attack on payment system was observed in the case of Home Depot a few years back;
The payment system of Home Depot was badly attacked by hackers which resulted in linking the credit card information of customers along with their purchase details, being sold online. This simple attack created a huge financial loss for Home Depot and affected the customers who made the payments in the last six months. This resulted in the company being sued despite compensating almost 50 million affected customers with a one-year free credit monitoring services.
In a survey of almost 4,000 directors of different companies in Australia, only half were reported to be cyber literate. As per the Department of Communication – Australian Government – the average cost of such cyber attacks for a business is around $276,000 which is why creating awareness of cyber security and threat attached to cyber attack is crucial to combat the issue globally.












