Skip to main content
  1. Home
  2. Computing
  3. News

Hackers stole passwords from 140,000 payment terminals using malware

Add as a preferred source on Google

An Android-based payment system has been affected by hackers who have been able to infiltrate its database and gain access to 140,000 payment terminals globally, according to TechCrunch.

The brand, Wiseasy, is well known in the Asia-Pacific region, with its payment terminals used in restaurants, hotels, retail outlets, and schools. Its accompanying Wisecloud cloud service is used for remote management and configuration for its customer’s terminals.

The Wiseasy point of sale system on a table.
Image used with permission by copyright holder

Hackers were able to gain access to Wiseasy’s systems through employees’ computer passwords being stolen by malware and ending up on the dark web marketplace, according to cybersecurity firm Buguard, which shared the information with TechCrunch.

Recommended Videos

Buguard is a penetration testing and dark web monitoring startup that observed the hacking of Wiseasy and noted that the bad actors were able to gain control of two of the company’s cloud dashboards, including an “admin” account. Notably, the popular payment system brand lacked commonly recommended security features, such as two-factor authentication.

The publication was able to view screenshots of Wiseasy’s “admin” user account, which shows how the service can control payment terminals remotely, have access to various user data, and have configuration control, such as being able to add users, seeing Wi-Fi names, and plaintext passwords of connected payment terminals. Access in the wrong hands can easily cause such a situation.

Buguard also said its attempts to warn Wiseasy of the security issue began in early July, but the scheduled meetings ended up getting canceled and were never held. At this point, Buguard chief technology officer Youssef Mohamed says he’s unable to say whether the breach has been resolved. However, a Wiseasy spokesperson, Ocean An, told TechCrunch that the company had fixed the issue in-house and added two-factor authentication to its systems.

It remains unknown whether Wiseasy will directly tell customers about this hack, however.

Many cyber-security issues have to do with hackers working to take over control of various programs or services from the back end. A recently resolved zero-day vulnerability was Follina (CVE-2022-30190), which granted hackers access to the Microsoft Support Diagnostic Tool (MSDT).

This tool is commonly associated with Microsoft Office and Microsoft Word. Hackers were able to exploit it to gain access to a computer’s back end, granting them permission to install programs, create new user accounts, and manipulate data on a device.

Early accounts of the vulnerability’s existence were remedied with workarounds. However, Microsoft stepped in with a permanent software fix once hackers began to use the information, they gathered to target the Tibetan diaspora and U.S. and E.U. government agencies.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
AI tools that help students cheat are multiplying, and the detectors can’t keep up
A New York Times report has found that cheating tools are evolving faster than the software meant to catch AI writing.
GPTZero website on a laptop

A wave of new apps marketed on TikTok and YouTube is making it nearly impossible for teachers to tell whether students are actually writing their own homework or offloading it to AI. The New York Times reports that tools known as humanizers and autotypers have closed the gap that used to give AI-written homework away, and that the same companies selling detection software are sometimes the ones helping students get around it.

The tools work around the checks teachers rely on

Read more
This monstrous ASUS gaming laptop costs as much as three new MacBook Pros
Asus’ flagship gaming laptop is back, bigger, brighter, and wildly expensive.
ASUS ROG Strix Scar 18 Computex 2026

Following up on the ROG Strix Scar 18 (2025)'s impressive act, ASUS has built a successor that looks even more ridiculous if you glance at the spec sheet. The ROG Strix Scar 18 (2026) is not a cute little café laptop. The flagship gaming machine is built around a large 18-inch 4K miniLED display and hardware that embarrasses most desktop PCs.

But all of this comes at a cost, and you might want to sit down for this one.

Read more
ASUS fanboys can now spend $16,578 on its 20th anniversary gaming gear
ASUS ROG Family Bucket Collector’s Edition Featured

ASUS’ Republic of Gamers brand is celebrating its 20th anniversary by bringing a five-figure collection of its coolest gaming hardware. The company just revealed pricing for its ROG 20th Anniversary Family Bucket Collector’s Edition, a monster bundle that costs 112,026 yuan, or roughly $16,578. The collection is apparently selling through an offline flash sale in Shanghai from June 20 to July 19, with buyers being selected through a lottery system.

This is more than your typical PC upgrade. ASUS is selling you the whole ROG lifestyle starter pack, which will attract collectors after their next limited edition bundle.

Read more