SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    7-Eleven's Bad App Design Let Criminals Steal More Than $500,000
Date    Friday July 12 2019, @02:18PM
Author    Fnord666
Topic   
from the stick-to-slurpees dept.
https://soylentnews.org/article.pl?sid=19/07/12/0146216

upstart writes:

Submitted via IRC for AnonymousLuser

7-Eleven's Bad App Design Let Criminals Steal More Than $500,000

Privacy and Security

Hundreds of 7-Eleven customers who downloaded a new mobile payment app in Japan were robbed out of hundreds of thousands of dollars due to some staggeringly idiotic security lapses in the app.

Yahoo Japan reports that 7-Eleven Japan released the 7pay app on July 1, and within a day customers started complaining about suspicious charges to their linked payment cards. On July 3, the company confirmed accounts could be accessed by third parties and announced it would stop charging credit and debit cards through the app.

According to the Yahoo report, hackers simply needed to input a customer's birthdate, phone number, and email address to request a password reset link. But it seems that a hacker could even request that the reset link be sent to whatever email address they wanted. It also seems that if a customer hadn't entered a birthdate, then the app would default to January 1, 2019, which would make it even easier for a fraudster to gain access.

Also at:
https://techbeacon.com/security/7-elevens-7pay-app-hacked-day-due-appalling-security-lapse https://www.engadget.com/2019/07/06/7-eleven-japan-app-security-loss/


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "7-Eleven's Bad App Design Let Criminals Steal More Than $500,000" - https://gizmodo.com/7-elevens-bad-app-design-let-criminals-steal-more-than-1836193161
  3. "Privacy and Security" - https://gizmodo.com/c/privacy-and-security
  4. "Yahoo Japan" - https://news.yahoo.co.jp/byline/mikamiyoh/20190704-00132766/
  5. "company confirmed" - https://www.sej.co.jp/company/important/20190703.html
  6. "https://techbeacon.com/security/7-elevens-7pay-app-hacked-day-due-appalling-security-lapse " - https://techbeacon.com/security/7-elevens-7pay-app-hacked-day-due-appalling-security-lapse
  7. "https://www.engadget.com/2019/07/06/7-eleven-japan-app-security-loss/ " - https://www.engadget.com/2019/07/06/7-eleven-japan-app-security-loss/
  8. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=34923

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, 7-Eleven's Bad App Design Let Criminals Steal More Than $500,000 on 2024-04-27 20:30:48