Seller of rigged PoS systems pleads guilty to Subway gift card hacking

Filed Under: Featured, Law & order, Malware, Security threats

Subway gift card CCShahin Abdollahi, former Subway franchise owner and a man accused of selling ready-to-hack point-of-sale (PoS) systems, pleaded guilty on Wednesday to running a gift card scheme that involved tampering with several other Subway stores’ computerized cash registers.

A 2013 indictment alleged that Abdollahi, 46, and his partner, Jeffrey Thomas Wilkinson, 35, both from California, carried out a fast-food crime spree by:

  • Hacking into at least 13 Subway PoS systems.
  • Fraudulently plumping up Subway gift cards by at least $40,000 in value.
  • Using some of the artificially inflated gift card balances to make purchases at Subway restaurants.
  • Selling other fraudulent cards on eBay and Craigslist.

The duo ran a number of Subway franchises in Southern California between 2005 and 2008.

During that time, they apparently learned quite a bit about PoS systems, so they quit selling sandwiches to instead start a business called "POS Doctor" to sell and install the systems into other Subway restaurants.

Those PoS systems weren't your ordinary, run-of-the-mill systems, mind you. They were rigged with a preconfigured, remote-access toolkit called LogMeIn that allowed the crooks to connect to the PoS systems after hours.

That's how they managed to regularly add fraudulent credit onto the Subway gift cards in at least 13 Subway outlets around the US.

Abdollahi pleaded guilty in US District Court for the District of Massachusetts to one count of conspiracy to commit computer intrusion and wire fraud and one count of wire fraud, according to the Department of Justice.

Abdollahi's sentencing is scheduled for 6 August 2014. His partner, Wilkinson, already pleaded guilty back in February and is scheduled for sentencing on 28 May.

, , , , ,

You might like

4 Responses to Seller of rigged PoS systems pleads guilty to Subway gift card hacking

  1. AP · 108 days ago

    LogMeIn. No rootkits, no hacks, no malware. Just an off-the-shelf remote access tool.
    It makes you wonder how many more of these are happening on a smaller scale, doesn't it?
    Maybe it's time to start carrying cash again.

  2. The thing that a lot of people probably don't realize is that Subway gift cards can be used online to purchase whatever you want, which makes them a lot more valuable. It's not just to go to Subway!

    • Cathy · 105 days ago

      Amy,
      what are you referring to when you say they can be used to purchase whatever you want?

  3. Mal · 108 days ago

    Wouldn't a "Sub of the Day" be a bit stale by the time it to arrives in the mail? ;)

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

I've been writing about technology, careers, science and health since 1995. I rose to the lofty heights of Executive Editor for eWEEK, popped out with the 2008 crash, joined the freelancer economy, and am still writing for my beloved peeps at places like Sophos's Naked Security, CIO Mag, ComputerWorld, PC Mag, IT Expert Voice, Software Quality Connection, Time, and the US and British editions of HP's Input/Output. I respond to cash and spicy sites, so don't be shy.