Redbox customers’ credit card numbers, private information stored in kiosks easily hacked

Redbox customers have been warned.

Old Redbox kiosks have been hacked to reveal customers’ credit card numbers and more of their private information, including their names, addresses and emails.

California-based programmer Foone Turing claimed in a social media thread last week that she was able to hack an old Redbox machine in Morganton, North Carolina.

It said it was able to find out customers’ name, ZIP code and usage history. They had rented the films “The Giver” and “The Maze Runner” nine years before the attack.

Redbox kiosk in Everett, Washington in 2022. ColleenMichaels – stock.adobe.com

According to Foone Turing, the hard drives in the Redbox machine had the first 6 digits and last 4 digits of the credit card used, as well as “other lower-level transaction details.”

Foone Turing told Ars Technica that it wasn’t a difficult task to find the customer data on the machine belonging to the beloved movie rental kiosk.

“The device has many registers and customer data is spread across several of them – usually fragmentary, but it is not very difficult to cross-reference them with other registers. It is not very simple to access the data directly,” he said. she.

Redbox Kiosks in Indianapolis. jetcityimage – stock.adobe.com

“Most of it is kept in an old database format that isn’t easy to manipulate, but anyone with basic hacking skills can easily pull the data manually from the files with a hex editor,” added the programmer.

Foone Turing explained that the “root issue” of the Redbox hacking situation “is that this is a machine that has to start itself, with no chance of a human putting in a decryption password or anything. That means the machine has to be able to decipher itself.”

Redbox’s parent company, Chicken Soup for the Soul Entertainment (CSSE), filed for bankruptcy in July.

The Wall Street Journal reported at the time that 24,000 Redbox rental kiosks were closing as the company moved to liquidate its assets.

Redbox kiosk in Santa Clarita, California. in May 2015. wolterke – stock.adobe.com

Judge Thomas Horan of the District of Delaware Bankruptcy Court, which is overseeing the case, granted the company’s request to pursue liquidation proceedings, saying, “there is no means to continue to pay employees, to pay any bills.”

Redbox’s liquidation reportedly leaves all 1,033 of its employees unemployed, and workers will not receive any severance or extended benefits.

In its Chapter 11 reorganization filings on June 28, CSSE listed $970 million in total debt and consolidated assets of $414 million as of March 31, 2024, Variety reported.

The company still owes money to Walmart and Walgreens — stores where some of its kiosks were located — and media companies, including Warner Bros. Home Entertainment and Sony Pictures Television.

Redbox was founded in 2002 and was a rival video store to Blockbuster, which has only one franchise store in the United States.

#Redbox #customers #credit #card #numbers #private #information #stored #kiosks #easily #hacked
Image Source : nypost.com

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top