Case Study
Retailer evaluates impact of credit card skimming attack with analysis from Unit 42
A global gas station retailer discovered a credit card skimming device placed on a POS terminal, installed by a threat actor using a tamper-evident overlay. Acting quickly, the company removed the device and engaged Unit 42’s Digital Forensics and Incident Response team. Unit 42 built a custom jig to extract data from the skimmer’s Bluetooth module and storage chip, identifying compromised cards and limiting customer notification to only those impacted. The investigation revealed tactics used and strengthened the retailer’s future defenses, allowing for precise incident scoping, minimized reputational damage, and improved readiness against similar threats.
