BlackCat ransomware knocked out NCR's Aloha point-of-sale platform
- Organization
- NCR Corporation
- Exploit
- Ransomware
- Industry
- Payment Technology
NCR Corporation, the payments and point of sale technology company formerly known as National Cash Register, suffered an outage beginning April 12, 2023 that took down parts of its Aloha platform for hospitality customers. On April 13 the company confirmed that a ransomware incident at one of its data centres was the cause, and it disclosed this to customers on April 15.
NCR characterised the impact as limited, describing a single data centre outage affecting a number of ancillary Aloha applications for a subset of hospitality customers, and said its investigation indicated no customer systems or networks were involved. In practice restaurants could still take payments in store, but many lost access to back office tools, payroll functions, loyalty and gift card processing and the Aloha Insight and Pulse dashboards. Counterpoint retail systems were also affected. NCR said more than 100,000 restaurant sites use the platform but declined to say how many were disrupted. Operators posted on the AlohaPOS subreddit, quoted by BleepingComputer, that they had reverted to pen and paper and were worried about meeting payroll.
The BlackCat group, also tracked as ALPHV, briefly posted about NCR on its leak site along with a fragment of what it said was a negotiation chat. The gang said it had not stolen data from NCR's own servers but claimed to hold credentials used to connect customers to services such as Insight and Pulse, and threatened to publish them if no ransom was paid. The post was later taken down.
NCR said it aimed to restore the affected applications within the week and offered temporary workarounds in the meantime.