A Tampa story
The Tuesday the processor called about the Hyde Park store
the owner of a three-store home-goods retailer with shops in Hyde Park, Carrollwood and downtown St. Petersburg
It is a Tuesday in October, a storm sitting in the Gulf that may or may not turn, and the owner of a three-store home-goods retailer is at the Hyde Park shop moving inventory off the floor in case it floods. Her card terminals run through a back-office computer in each store. Her point-of-sale vendor installed a remote-support tool on all three so they can fix things without driving across the Howard Frankland.
The remote tool still uses the password the vendor set on install day. Someone in another country runs a program that tries that password against thousands of stores an hour. In September it worked on Hyde Park. Since then a small piece of software has copied each card as it was swiped.
The owner does not know any of this. What she knows on Tuesday is that the sandbags are in place and the register is running. The processor's fraud team knows something else.
At 11:20 a.m. the processor calls to say that forty cards used at the Hyde Park store last month have since been used for fraud in three other states, and her store is the one thing they have in common.
What changes the ending
- Default passwords changed, and remote-support tools locked to the vendor's addresses and switched on only while a ticket is open (CIS 4 Secure Configuration of Enterprise Assets and Software)
- Card terminals on their own network segment, away from the back-office PC that reads email, so one wrong click cannot reach a swipe (CIS 12 Network Infrastructure Management)
- The point-of-sale vendor's access reviewed, written down and monitored like any other login, because the 2026 DBIR found 68% of retail breaches involve a third party (CIS 15 Service Provider Management)