Home
Blog
Point-of-Sale Malware: What Small Retailers Need to Know About Card-Skimming Software

Point-of-Sale Malware: What Small Retailers Need to Know About Card-Skimming Software

Reviewed by
Table of Contents

Key Takeaways

Picture a busy Saturday afternoon at your shop. Customers are paying, transactions are going through, everything looks fine. But running silently in the background, software you didn't install is capturing every card number that passes through your terminal and sending it to a server halfway around the world.

That's point-of-sale malware. And it's more common than most small business owners realize.

You don't need to be a major retailer to be a target. Your POS system holds exactly what attackers want: live payment card data from real customers making real purchases. The theft is quiet, the damage takes time to surface, and by the time anyone notices, hundreds of cards may already be compromised.

This guide breaks down exactly how POS malware works, how it gets onto your systems, what warning signs to watch for, and, most importantly, what practical steps you can take right now to protect your business and your customers.

How does POS malware actually work?

Most people assume payment card data is encrypted the moment a customer taps or swipes. That's mostly true, but there's a gap.

For a brief moment during processing, card data exists in your terminal's memory (RAM) in an unencrypted state. The system needs to read and validate the data before it can encrypt and forward it to the payment processor. That window, sometimes just milliseconds, is when POS malware strikes. This technique, called RAM scraping, was the method behind some of the largest retail data breaches in history, including the 2013 Target breach that exposed roughly 40 million card numbers. As Malwarebytes explains, RAM scraping exploits the brief window during which card data exists in plaintext before it's encrypted.

What makes RAM scraping particularly dangerous is how invisible it is during normal operations. The terminal appears to be functioning perfectly. Transactions complete normally. Receipts print. Nothing looks wrong to the cashier, the customer, or the manager reviewing end-of-day reports. The malware simply watches memory, grabs card data as it briefly appears in plaintext, logs it, and periodically sends it out in encrypted batches to an attacker-controlled server.

According to Malwarebytes Labs, the security industry currently tracks more than 15 distinct families of POS malware, including well-known variants like BlackPOS, Backoff, Dexter, and Alina. Each works a little differently, but the goal is the same: capture card data silently and exfiltrate it without triggering alerts.

POS malware generally falls into three categories:

  • Memory scrapers (RAM scrapers): Sit in your terminal's RAM and grab card data during the fraction of a second before encryption kicks in. This is the most common type and the one responsible for the biggest known breaches.
  • Keyloggers: Record everything typed into the system, including PINs, admin passwords, and login credentials, then send it to an attacker's server. Keyloggers are especially damaging because they can harvest credentials that give attackers ongoing access long after the initial infection.
  • Network sniffers: Intercept card data as it travels between your terminal and the payment processor, especially dangerous when network traffic isn't properly encrypted end-to-end.

BlackPOS, the malware tied to the Target and Home Depot breaches, works by infiltrating POS endpoints via stolen credentials or phishing, then scraping memory for cardholder track data, the full magnetic stripe information that can be used to clone a physical card. As Huntress notes, variants of BlackPOS continue to evolve and remain an active threat in 2025. The Backoff family, meanwhile, became so widespread that the U.S. Department of Homeland Security issued a specific advisory warning businesses about it, a sign of just how seriously the threat is taken at a national level.

Understanding these mechanics matters because it shapes how you defend against them. The gap that RAM scrapers exploit exists at the hardware and software level of your terminal. Closing it requires specific technical controls, not just general good practices.

How does the malware get onto your system?

This is the part that surprises most small retailers: attackers don't always need to physically touch your terminal.

According to Stripe, common entry points include phishing emails sent to staff, compromised or weak administrator credentials, and known vulnerabilities in outdated POS software.

Here's the realistic scenario for a small business:

  1. An employee receives a convincing email with a file attachment (disguised as an invoice or a software update notice).
  2. They open it. Malware installs itself on a computer connected to the POS network.
  3. The attacker moves laterally through the network to reach the payment terminals.
  4. Card data is captured silently and sent out in encrypted batches.

The initial breach often has nothing to do with the POS system itself. It's a phishing email to someone in accounting, a reused password on a remote-access tool, or a POS software installation that hasn't been updated in two years. This is an important point: attackers frequently use your POS system as the final destination, not the entry point. They get in through a softer target (an employee's email account, a poorly secured remote desktop connection, or a vendor with access to your network) and then work their way toward the payment terminals.

Remote access tools deserve special mention here. Many small businesses use remote desktop software so that their POS vendor or IT support can troubleshoot issues without coming on-site. That's convenient, but if those tools are protected by weak or default credentials, they become an open door. Attackers routinely scan the internet for exposed remote desktop ports and attempt to log in using common username and password combinations. A successful login gives them the same access as a legitimate technician, including the ability to install software on your terminals.

Third-party vendors are another underappreciated risk. If a supplier, accountant, or technology partner has access to your network and their own systems are compromised, that connection can become a pathway into your environment. This is sometimes called a supply chain attack, and it's exactly how the 2013 Target breach began, through credentials stolen from an HVAC contractor that had network access to Target's systems.

For small retailers, the takeaway is that protecting your POS system means thinking about your entire network and everyone who touches it, not just the terminal sitting on your counter.

What are the warning signs of a POS infection?

POS malware is built to hide. But there are signals worth watching for, and knowing them can mean the difference between catching an infection early and discovering it months later through a wave of customer fraud reports.

Slower terminal performance. Malware running in the background uses system resources, CPU cycles and memory, that your terminal needs to process transactions. If your terminals have become noticeably sluggish without an obvious explanation, such as a recent software update or increased transaction volume, that's worth investigating. A terminal that used to process a tap payment in under a second and now takes three or four seconds is showing a symptom, not just an inconvenience.

Unusual outbound network activity. Malware exfiltrates data to remote servers, usually at night or during low-traffic periods to avoid detection. If your network monitoring shows unexpected outbound connections, particularly to unfamiliar IP addresses or foreign servers, take note. Many small businesses don't actively monitor outbound traffic, which is exactly why attackers feel comfortable sending data out over extended periods.

Fraud reports from customers. When customers start reporting unauthorized charges shortly after shopping at your store, that's a serious sign. The fraud may appear days or weeks later as stolen card data gets sold on underground markets and then used by buyers. A cluster of fraud reports from customers who all visited your store in a similar timeframe is a strong indicator that your systems may be compromised.

Unfamiliar processes or files on your POS systems. As Huntress explains, active BlackPOS infections often leave traces: suspicious running processes, unauthorized binaries, and unusual connections to foreign IP addresses. If you or your IT support person notices software or processes on your terminal that you don't recognize and didn't install, treat it as a red flag until proven otherwise.

Admin account changes you didn't make. New logins, changed passwords, or unfamiliar user accounts on your POS system are a red flag for credential-based intrusions. Attackers who gain access to your system often create their own administrator accounts so they can maintain access even if the original vulnerability is patched.

Unexpected reboots or configuration changes. If your terminals are restarting at odd hours or settings have changed without anyone on your team making those changes, it may indicate that someone else has remote access to your systems.

None of these signs is definitive on its own, but any of them warrants a closer look. The businesses that catch infections early are usually the ones that have established a baseline of what normal looks like, so that anything abnormal stands out.

Does chip technology (EMV) protect you?

Partially, but not completely.

EMV chip cards significantly reduced counterfeit card fraud at physical terminals because the chip generates a unique transaction code for each purchase, a code that can't be reused to make fraudulent transactions elsewhere. Before EMV became widespread in the United States, stolen magnetic stripe data could be encoded onto a blank card and used at any terminal. The chip made that kind of cloning far more difficult. That's a real and meaningful improvement, and fraud rates at chip-enabled terminals did fall substantially after EMV adoption.

But chip technology doesn't eliminate POS malware entirely, and attackers have adapted their methods accordingly.

Some malware now targets card-not-present data (the card number, expiration date, and CVV needed to make purchases online) which chip cards don't protect. A stolen chip card number is still fully usable for e-commerce transactions, and online fraud has grown significantly as in-person counterfeit fraud has declined. This shift is sometimes called the "balloon effect": squeeze fraud in one place and it expands somewhere else.

Network sniffers can still intercept data in transit if your payment traffic isn't properly encrypted end-to-end. EMV protects the card authentication process, but if the data traveling between your terminal and your payment processor isn't secured with strong encryption, it can still be captured on the network.

Magstripe fallback is another lingering vulnerability. Many terminals still accept magnetic stripe transactions as a fallback when a chip can't be read, whether because the chip is damaged or because the terminal prompts for it. Attackers are aware of this and have developed techniques to force fallback transactions in some environments.

The chip raised the bar significantly. It made large-scale counterfeit card fraud much harder to execute. But it didn't close the door on POS malware, and treating EMV as a complete solution leaves meaningful gaps in your defenses.

What can small retailers do to protect themselves?

The good news: most POS malware infections are preventable. The steps below aren't complicated, but they require consistency and follow-through. A security measure that's set up once and then forgotten provides much weaker protection than one that's actively maintained.

Keep your POS software updated. Outdated software is the most exploited entry point for POS malware. When vendors discover vulnerabilities in their software, they release patches to fix them, but those patches only protect you if you install them. Schedule updates regularly, don't skip them, and if your POS vendor announces a critical security patch, treat it as urgent. Running software that's two or three versions behind is the equivalent of leaving a known unlocked window in your store.

Separate your POS network from everything else. Your payment terminals should not share a network with your office computers, guest Wi-Fi, or any other systems. This practice, called network segmentation, is one of the most effective structural defenses available to small retailers. It means that even if an attacker compromises one device on your network (say, through a phishing email opened on an office computer) they can't easily reach your payment terminals. Setting up a separate network for POS systems typically requires a router configuration change and is something most IT professionals can implement in a single visit.

Use strong, unique credentials. Default admin passwords are a known and widely exploited vulnerability. Change them immediately on any new device or software installation. Use different passwords for every system, reusing the same password across your POS software, your router, and your email means that one compromised password can unlock everything. Consider a password manager to keep track of complex, unique credentials without having to memorize them.

Train your staff to spot phishing. Most POS malware infections start with a human click on a malicious email attachment or link. Regular, practical training on how to recognize suspicious emails (unexpected attachments, urgent requests for credentials, sender addresses that look slightly off) is one of the highest-return security investments a small business can make. Even a single 30-minute training session can meaningfully reduce the likelihood that an employee opens the wrong attachment.

Work with PCI DSS-compliant payment processors. The Payment Card Industry Data Security Standard (PCI DSS) sets baseline security requirements for any business that handles card payments, covering everything from network security to access controls to encryption. As the U.S. Chamber of Commerce notes, compliance is required by most merchant account providers, and failing to meet it can expose you to fines and liability if a breach occurs. Working with a processor that takes PCI compliance seriously, and helping you meet your own compliance obligations, is an important layer of protection.

Monitor your systems for unusual activity. This doesn't require a dedicated security team or expensive software. Many modern POS systems and endpoint protection tools can flag unusual processes or unexpected outbound connections and send you an alert. Set up those alerts, review them regularly, and investigate anything that doesn't look familiar. Establishing a routine, even a weekly five-minute check of your network activity logs, creates the habit of noticing when something is off.

Use point-to-point encryption (P2PE). This encrypts card data the moment the card is read by the terminal, before it ever touches your system's memory in a usable form. It's one of the most effective defenses against RAM-scraping malware specifically, because it eliminates the window of time during which card data exists in plaintext. If your current payment processor or terminal doesn't support P2PE, it's worth asking about upgrading, the protection it provides is substantial.

Limit remote access and audit who has it. If your POS vendor or IT support uses remote access tools to manage your systems, make sure those connections are protected with strong credentials and, ideally, multi-factor authentication. Regularly review who has remote access to your network and revoke access for vendors or individuals who no longer need it.

The cost of getting this wrong

A POS malware incident isn't just a security problem. It's a business problem with financial, operational, and reputational dimensions that can persist long after the malware itself has been removed.

There's the direct cost: forensic investigation to determine how the breach occurred and what data was taken, card reissuance fees charged by card networks to cover the cost of replacing compromised cards, and potential fines for PCI non-compliance. These costs can add up quickly. Forensic investigations alone can run into the tens of thousands of dollars, and card network fines for non-compliant merchants who experience a breach can be substantial.

There's the operational disruption while your payment systems are locked down or replaced. Depending on the severity of the incident, you may need to take your terminals offline, switch to cash-only transactions, or temporarily close while the investigation is underway. For a retail business that depends on card payments, which is most of them, even a few days of disruption can represent significant lost revenue.

There's the customer trust impact, which is harder to put a number on but often longer-lasting than any fine. Customers who learn that their card data was stolen at your store may not come back. They may tell others. In an era when online reviews and word-of-mouth travel quickly, a publicized breach can damage a small retailer's reputation in ways that take years to rebuild, if recovery is possible at all.

And there's the time cost. Responding to a breach, working with investigators, communicating with affected customers, dealing with your bank and payment processor, and implementing remediation measures is an enormous drain on the owner's time and attention, time that isn't being spent running the business.

For small retailers operating on tight margins, a single breach can be genuinely threatening to the business's survival. The retailers who get through these incidents are almost always the ones who had basic protections already in place, because there was less damage to contain and a clearer path to recovery. Prevention is not just cheaper than response, in many cases, it's the difference between a business that survives and one that doesn't.

Conclusion

Point-of-sale malware isn't something that only happens to big chains. Small retailers process real card data from real customers every day, and that data has real value to the people who steal it.

The protections aren't complicated. Updated software, separated networks, trained staff, and encrypted payment traffic go a long way. You don't need to be a security expert to run a secure store, but you do need to take this seriously before something goes wrong rather than after.

It's also worth remembering that POS security doesn't exist in isolation. The same employees who click a phishing link that installs POS malware may also be exposing personal accounts, business email, or financial credentials. A layered approach to security (covering your terminals, your network, your staff habits, and your personal digital footprint) gives you the best chance of catching a threat before it becomes a crisis.

If you want to know where your own digital security stands right now, get a free security scan with Guardio today and stay protected.

CMS-based CTA:
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

What is point-of-sale malware?

Point-of-sale (POS) malware is software built to steal payment card data from retail checkout terminals. It typically works by scraping card numbers from the terminal's memory during the brief moment before the data is encrypted. Common types include RAM scrapers, keyloggers, and network sniffers, and the stolen data is sent to remote servers controlled by attackers.

How does POS malware get installed on a business's system?

POS malware most commonly enters a business through phishing emails sent to employees, compromised or weak administrator credentials, or unpatched vulnerabilities in outdated POS software. The malware doesn't always target the terminal directly. It often gets onto a connected office computer first, then spreads through the network to reach payment systems.

Can chip card technology prevent POS malware attacks?

EMV chip cards reduce certain types of payment fraud, particularly counterfeit card use at physical terminals, but they don't fully prevent POS malware attacks. Attackers have adapted by targeting card-not-present data useful for online fraud, and network-based malware can still intercept payment traffic when end-to-end encryption isn't properly configured.

What are the warning signs that a POS system may be infected?

Warning signs of a POS malware infection include noticeably slower terminal performance, unusual outbound network activity especially at off-hours, customers reporting fraudulent charges after visiting your store, unfamiliar files or processes on POS devices, and admin account changes that weren't authorized by the business.

What is RAM scraping in the context of POS malware?

RAM scraping is a technique where malware reads unencrypted payment card data from a terminal's memory during the brief moment between card swipe and encryption. Because card data must be temporarily decrypted for processing, there is a short window that attackers exploit. RAM scraping was used in major retail breaches including the 2013 Target attack that exposed roughly 40 million card numbers.

Do small businesses need to worry about POS malware?

Yes. Small retailers are frequent targets precisely because their POS systems tend to run older software, use weaker credentials, and lack the network segmentation that larger retailers maintain. Attackers look for the easiest entry points, not the biggest targets, and a small business processing hundreds of card transactions a day holds significant value to criminals.

What is PCI DSS and why does it matter for small retailers?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for any business that accepts, stores, or transmits payment card data. It covers firewalls, strong passwords, encrypted card data, and regular system monitoring. Most merchant account providers require compliance, and non-compliant businesses can face fines and increased liability if a breach occurs.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now