A Atlanta story
The Tuesday three stores' card terminals almost started paying someone else
the founder of a three-store specialty grocer with locations in Decatur, Buckhead and Alpharetta
It is a Tuesday in October, pollen long gone, and the Decatur store opens at seven. The founder started with one storefront off the square twelve years ago. Now there are three, and every one of them lives on cards: eleven thousand swipes a week, every one of them somebody's trust.
The back-office PC in Decatur runs a remote support tool the point-of-sale vendor installed in 2023. The vendor fixed a flaw in it in August. Nobody at the store was told, so nobody patched it. At 5:50 that morning someone in another time zone walks through it and drops a program that reads card numbers from memory before they are encrypted.
The three back-office machines share one flat network. By 6:08 the program is on all of them.
The engineer isolates the three machines and calls the founder at 6:14, before the first customer. The card terminals sit on their own network segment and never saw the program. The stores open at seven, the cards run clean, and the quarterly PCI questionnaire gets answered with Tuesday's log instead of a guess.
At 6:11 the protection agent on the Buckhead machine catches the program waiting for the first card of the day and stops it.
What changes the ending
- Card terminals on their own network segment, so a back-office PC cannot reach them even when it is owned (CIS 12 Network Infrastructure Management).
- Patching the remote tools and the point-of-sale software the week the fix ships, because 42% of retail breaches start with a known flaw (CIS 7 Continuous Vulnerability Management).
- A protection agent on every register and back-office PC that stops a memory scraper before the first swipe (CIS 10 Malware Defenses).