Research Library / Case Studies /

Oil & Gas / Retail Fuel Infrastructure

Device Tamper Prevention Through Security Testing

One of India's largest Oil and Gas companies asked Payatu to find the break-in points in its fuel dispensers and display units before fraudsters did. In one week, testers falsified display readings by voltage manipulation, sniffed and injected keypad data to recover maintenance passwords, and tampered with printer output, exposing fraud paths worth millions.
IoT Security Assessment

At a glance

INDUSTRY

Oil & Gas / Retail Fuel Infrastructure

CLIENT PROFILE

One of India's largest Oil and Gas companies

SERVICES

IoT Security Assessment

ENGAGEMENT

One-week assessment of fuel dispensers and display units

Key Takeaways

  • Client – One of the titans of India's Oil and Gas industry, operating fuel dispensers and display units across its fuel stations.

  • Problem – The client needed to know whether its fuel dispensers and display units, connected over a local network at each station, could be tampered with to falsify readings or leak data.

  • What Payatu did – Tested display units, keypad data entry devices and receipt printers for tampering and injection vulnerabilities across the client's fuel station equipment.

  • Outcome – Found that display readings could be falsified, keypad data sniffed and injected to recover maintenance-only passwords, and printer output tampered with, helping prevent fraud worth millions within a one- week assessment.

the challenge

Why the client called us in

Data tampering with fuel quantity and amount is a persistent problem at fuel stations across India, and any fraud discovered on a major Oil and Gas company's equipment puts its reputation at stake. The client's display devices were connected over the local network at each fuel station, and it needed to know exactly where the break-in points were before fraudsters found them first. The client brought in Payatu to assess its fuel dispensers and connected display units.

  • Identify break-in points that could allow data leakage from station equipment
  • Determine whether display units could be tampered with to falsify readings
  • Assess whether fuel dispensers and printers could be manipulated by an external device

scope of engagement

What was in scope

  1. Display unit tampering assessment
  2. Keypad data entry device assessment
  3. Printer communication assessment

Our Approach

How Payatu ran the engagement

01

Display Manipulation Testing
Manipulated display units by tampering with data such as fuel quantity, density and cost through voltage level manipulation, and confirmed the display could be falsified simply by connecting an external device.

02

Keypad Sniffing and Injection
Used a logic analyzer to sniff keystrokes on data entry devices and injected false parameters over the keypad line, recovering confidential parameters known only to product maintenance engineers.

03

Printer Manipulation Testing
Sniffed communication to extract end-user information from printer slips and changed printer values by tampering with the communication port.

Key findings

What we found

Display Manipulation
Display units could be falsified by voltage level manipulation or by connecting an external device, altering shown fuel quantity, density and cost.
Keypad Sniffing and Injection
A logic analyzer could sniff keystrokes on data entry devices and inject false parameters over the keypad line, exposing confidential passwords known only to maintenance engineers.
Printer Manipulation
Communication port tampering allowed extraction of end-user information from printer slips and modification of printed values.

the outcome

Results and Impact

Payatu's one-week assessment gave the client a clear picture of how its fuel dispensers and display units could be tampered with, helping prevent fraud worth millions and protecting the company's reputation at the pump.

  • Display falsification paths via voltage manipulation and external devices identified

  • Keypad sniffing and injection risk exposing maintenance passwords flagged

  • Printer tampering path allowing data extraction and value manipulation closed

  • Fraud prevention worth millions achieved within a one-week engagement

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment