October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

FIN6: How the Cybercrime Group Stole Payment Cards from PoS Systems

FIN6 stole payment-card data from compromised PoS systems and later targeted e-commerce checkout pages. Here is how its reported methods worked and what merchants can do to reduce risk.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FIN6 is a financially motivated cybercrime group known for breaking into retailers and hospitality businesses to steal payment-card data. FireEye reported in 2016 that some FIN6-linked breaches were associated with more than 10 million cards identified on an underground card shop. Its methods later expanded beyond in-store point-of-sale (PoS) systems to include e-commerce checkout pages and, according to Mandiant, ransomware.

What is FIN6?

MITRE ATT&CK identifies FIN6 as group G0037 and describes it as a cybercrime group that steals payment-card data to sell for profit. The group has also been associated with the names Magecart Group 6, ITG08, Skeleton Spider, TAAL and Camouflage Tempest. Its reported targets have included retailers and hospitality businesses.

FireEye Threat Intelligence reported in 2016 that FIN6-linked victim data had appeared on an underground card shop as far back as 2014. In some cases, the shop displayed more than 10 million cards associated with breaches linked to the group. That figure describes cards identified on the shop in FireEye’s reporting; it is not a claim that every card was taken in one incident or that all were necessarily stolen directly by FIN6.

How did FIN6 steal cards from PoS systems?

FIN6’s reported activity involved gaining access to a business network, moving through it toward payment systems, collecting card data, and sending that data out for monetization. MITRE ATT&CK procedure examples document the following behaviors:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Gain access and expand it: Use of valid accounts and exploitation for privilege escalation, followed by network and service discovery.
  2. Reach systems that handle payments: Use of Windows services and remote services to move within a compromised environment.
  3. Collect card data: Scripts and malware were used to collect payment-card data from compromised PoS systems. Visa’s February 2019 report identifies TRINITY, also called FrameworkPOS, in FIN6 PoS compromises.
  4. Stage and transfer data: MITRE records compression and remote staging, followed by HTTP POST exfiltration. Its examples also include PowerShell, Cobalt Strike and antivirus disabling.
  5. Sell stolen data: FireEye traced FIN6-linked data to an underground card shop, where listings sometimes exceeded 10 million cards.

How did the group move from PoS attacks to e-commerce skimming?

Visa’s February 2019 report describes a shift in approach when FIN6’s PoS deployment was blocked: investigators observed malicious code injected into e-commerce checkout pages to steal card-not-present (CNP) data. In this kind of attack, the target is the online checkout experience rather than a payment terminal in a store. Visa wrote that FIN6 “has fully incorporated targeting CNP environments into their criminal methodology.”

The distinction matters to merchants because securing PoS devices alone does not protect payment details entered on a website. Checkout code and the systems that can change it are also sensitive payment assets.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

How did FIN6 make money, and what changed with ransomware?

In the card-theft operation documented by FireEye, stolen payment data was offered through an underground card shop. Mandiant reported on April 4, 2019, that FIN6 had also expanded into ransomware deployments to monetize access to organizations that did not have payment-card data worth stealing. The reporting describes ransomware as an additional way to profit from compromised access, not as a replacement that proves the group stopped stealing cards.

Approach What is targeted How the activity is monetized Evidence described
PoS compromise Payment-card data on compromised in-store systems Sale of stolen card data on an underground card shop MITRE ATT&CK; FireEye Threat Intelligence, 2016
E-commerce skimming Card-not-present data entered on checkout pages Card-data theft and sale Visa, February 2019
Ransomware Organizations whose access could be monetized even without payment-card data Ransomware deployment Mandiant, April 4, 2019
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can merchants do to reduce the risk?

The controls below are defensive measures mapped to the behaviors reported by MITRE, Visa and Mandiant. They are not a guarantee against compromise; they aim to make access harder, expose unauthorized changes sooner and support a faster response.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Protect PoS and checkout environments: Segment payment systems from general business networks and limit which users and services can reach them. Treat online checkout code and the systems that deploy it as high-value assets.
  • Watch for unauthorized checkout changes: Use application-integrity monitoring and review or alert on unexpected scripts and changes to payment pages.
  • Limit and protect administrative credentials: Restrict privileged access to named users and systems, and monitor for unusual account use or remote-service activity.
  • Use endpoint detection and response: Look for suspicious PowerShell or other script activity, discovery behavior, attempts to disable antivirus, and unexpected data staging.
  • Monitor outbound traffic: Investigate unusual transfers, including unexpected HTTP POST activity from PoS or checkout-related systems.
  • Maintain an incident-response plan: Define how to isolate affected systems, investigate potential payment-data exposure, and restore trusted PoS and checkout environments.

These measures address risks to payment information; merchants should also follow the payment-security requirements applicable to their business and payment environment.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.