forumNew topic

Are POS terminals at the point of sale being hacked? How secure is credit card data?

DDoruk A***Member
Job title
Business Owner
Sector
Software
Organization type
300-person organization
Joined
Apr 2023
Message
18
#1

We have a POS terminal in our shop, customers swipe their credit cards. The POS is a very old model, the network connector is barely working. Can a hacker compromise this device and steal all the cards? If it's not connected to the network, is there still a risk?

The POS manager said 'PCI-DSS compliance' is required but what does that mean? Do I need to update the device? Where do I look for software updates?

How do I delete records (card numbers, passwords) from the device? If I sell the device, will the data be exposed? If I switch to another operator company, do all the records stay with them?

EEsra S***MemberCommunity member
Joined
Jan 2026
Message
367
Most Helpful#2

POS (Point of Sale) devices handle highly sensitive credit card data. PCI-DSS (Payment Card Industry Data Security Standard) is mandatory. Steps: 1) PCI-DSS compliance: business certification, quarterly security assessment, 2) Hardware: replace old POS with new model (EMV chip reader + contactless), 3) Encryption: end-to-end encryption (encrypted transmission of card data), tokenization (token instead of real card number on POS), 4) Network: POS → Payment Processor (secured channel), 5) Software: latest firmware (security patches), regular updates, 6) Access: strong admin password, transaction logs, 7) Data retention: don't store cards, truncate receipts (last 4 digits only), 8) Network disconnected POS: offline mode (batch upload later, has risks), 9) Device sale: secure wipe (data destruction), get witnessed deletion certificate from manufacturer, 10) POS provider: check compliance clauses in contract with payment processor (Stripe, iyzico, Getnet). In Turkey: KVKK compliance is required, keeping card data minimal is mandatory. Old POS hacking risks: malware installation (keylogger, memory scraper), data theft if network-connected, physical access needed if network-isolated.

EEmine C***New member
Job title
Clinic manager
Sector
Retail
Organization type
family business
Joined
Sep 2026
Message
1
#3

if the pos is an old model replace it get a new device. ask the company about pci-dss compliance, they know. keep card data encrypted, truncate receipts (show 1234, hide the rest). do firmware updates regularly...

TTolga K***ExpertCommunity member
Joined
Apr 2025
Message
24
#4

PCI-DSS requirements: 1) Network segmentation (POS → Payment network), 2) Firewall rules (POS-only ports), 3) Encryption (AES-256, TLS 1.2+), 4) Access control (strong password, key management), 5) Vulnerability scanning (quarterly), 6) Intrusion detection, 7) Data retention (minimized), 8) Incident response plan. Terminal software: check Verifone, Ingenico firmware updates. Tokenization: payment processor manages tokens, don't store card numbers in POS memory. Offline mode risk: batch settlement delays, high chargeback risk.

KKemalNew member
Job title
Farm business
Joined
Sep 2024
Message
42
#5

don't use the old POS 2024 EMV terminals are very cheap. if you're going to do PCI-DSS compliance, ask your payment processor, they'll help too. keep card data encrypted, tokenized — the real number shouldn't appear anywhere. if you sell the device you'll do a secure wipe, get a warranty certificate...

EEmre G***MemberCommunity member
Joined
Dec 2022
Message
198
#6

POS security layers: 1) Hardware (tamper-proofing, secure boot), 2) Software (signed OS, verified updates), 3) Communication (TLS 1.2+, certificate pinning), 4) Data (encryption, tokenization, key management), 5) Compliance (PCI-DSS self-assessment, SAQ, audit). Transition: old POS → new POS, data migration (wiping the old device). Incident: card breach → PCI notification, breach disclosure, forensic investigation.

DDoruk U***Member
Job title
Technical service technician
Sector
Cosmetics
Organization type
two-branch business
Joined
Aug 2025
Message
137
#7

20 years managing POS systems, biggest mistake is using old hardware. Old terminals don't get firmware security patches, making them malware targets. New terminal (chip + contactless, tokenized) + proper VLAN + PCI audit = safe. If you don't store card data on the machine, you won't be a hacker target.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#8

I have no experience with pos terminal security so I'm asking. If permission and scope aren't in writing don't start that test.

Of course it varies if your situation is different.

AAyşe Y***MemberCommunity member
Joined
Jun 2024
Message
10
#9

i felt relieved reading this answer, so it's not just me. like taking measures without an inventory leaves doors you haven't seen open.

when making a decision first look at what data you have on hand.

PPelin D***Expert
Job title
Finance Manager
Organization type
early-stage startup
Joined
Nov 2023
Message
138
#10

The opposite happened to me, that's why I'm writing. Hasty decisions become decisions you have to fix six months later.

Just leaving this note, it might be useful.

GGökhan C***Member
Job title
Purchasing manager
Sector
Printing
Organization type
medium-sized business
Joined
Jun 2022
Message
181
#11

Let me summarize the topic, since several different answers were given. If permission and scope aren't in writing, don't start that test.

If I were you, I'd go this route.

RReyhan A***Member
Job title
Digital marketing specialist
Sector
Jewelry
Organization type
regional distributor
Joined
Oct 2024
Message
97
#12

Good call starting this thread.

LLevent B***MemberCommunity member
Joined
Feb 2025
Message
24
#13

We need to take it step by step. Any unwritten clause becomes a point of disagreement later as both sides remember it differently.

MMeryem U***Member
Job title
Secretary
Sector
Packaging
Organization type
family business
Joined
Nov 2023
Message
300
#14

I'd appreciate it if you shared the outcome.

FFurkan U***MemberCommunity member
Joined
Apr 2023
Message
163
#15

I have a question. An untested backup is not a backup.

An automated scan report is not the same as a penetration test. Proven by experience.

OOnur Y***Member
Job title
Social media manager
Sector
Leather
Organization type
regional distributor
Joined
Aug 2025
Message
120
#16

Saved.

AAyşe Ç***Member
Job title
Chief Information Security Officer
Sector
Construction
Organization type
cooperative
Joined
Feb 2025
Message
27
#17

Let me share what happened to me; it might be useful. If you don't write this down from the start, it leads to arguments later.

That's all, sorry if I went on too long.

YYağmurNew member
Job title
Travel blogger
Joined
Oct 2024
Message
46
#18

We got stuck at the same point for a while. tbh an automated scan report is not the same as a penetration test.

I'm also curious if anyone does it differently.

LLale G***Member
Job title
Call center representative
Sector
Glass
Organization type
chain store
Joined
Feb 2024
Message
172

Doki · E-commerce infrastructure · 2025

#19

I'm a small business, let me explain from my side. Solutions that work at a small scale collapse when you grow; I learned this late.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. I'm also curious if anyone does it differently.

ZZübeyde K***Member
Job title
Purchasing manager
Sector
Sports and fitness
Organization type
family business
Joined
Feb 2025
Message
165

Doki · Corporate website · 2026

#20

let me share what happened to me; it might be useful. solutions that work at a small scale collapse when you grow; I learnned this late.

just leaving this note, it mgiht be useful.

Reply