Buy Now, Pay Later Apps: Curbing The Ransomware Threat

Mar 21, 2023 | Privacy, Security

by Jeff Broth

Buy now pay later (BNPL) is one of the fastest growing fintech segments. What began as an alternative payment method has blossomed into a major industry that has given physical and online retailers a sales boost even during tough times.

BNPL apps are easy to use and consumer-oriented. While these features make them fantastic to scale, they also present cybersecurity risks. As BNPL usage increases, more consumers could potentially risk identity theft or worse.

Ransomware attackers are increasingly turning their attention to BNPL apps. Here are a few ways they could weaponize a BNPL app against consumers.

 

Emulation

This threat isn’t necessarily restricted to consumers. Malicious actors typically use emulators to scam a BNPL app out of funds. For instance, an attacker could use an emulator to create a string of accounts, buy goods without the intention of paying, close those accounts, and flip goods on the marketplace.

These types of attacks defraud the app and could lead to business closure. However, ransomware attackers can use emulators to increase the damage they cause. They could potentially create accounts embedded with malicious software and emulate genuine customer accounts.

These actions could cause the app’s software to mistake the malicious account for the real one, leading to potential data theft. For instance, reporting an issue on the app could lead to the app’s customer support divulging information the attacker needs to steal funds or purchase goods fraudulently.

Blocking automated environments like ADB and preventing the app from running on emulators are the best ways of preventing emulators from creating ransomware nightmares.

 

Overlays

Screen overlays are a common threat for every app, not just BNPL ones. In this method, an attacker creates a genuine-looking screen and overlays it on top of the real one. If the customer does not spot the minor differences, they enter their login information and password, giving attackers several ways to exploit that information.

Typically, attackers hold the account for ransom, along with the user’s personal data. This is damaging for the app too because the attacker can execute several purchases without any intention of repaying. Keyloggers are another threat similar to screen overlays.

Keyloggers record the keystrokes on the user’s device, giving attackers access to passwords and login IDs. Thankfully, preventing these kinds of attacks is relatively straightforward. App security teams must block keyloggers and overlays and disable login screens if attackers bypass these controls.

Monitoring and encrypting data flowing into the app is also a good way to ensure users don’t lose any sensitive information. While it is impossible to fully secure a user’s device since the app does not have any control over it, BNPL security teams can enforce MFA authentication.

Here, it is essential to use authenticator apps instead of one-time passwords. If a user’s device is compromised, an OTP won’t be of much use. An authenticator app will secure the device and prevent attackers from piggybacking in on the user’s login credentials.

App security teams must also communicate what kind of information they’ll ask from users. For instance, many banking apps suffer breaches because users divulge critical information to attackers posing as bank employees. BNPL apps must use the lessons banking apps have learned from these incidents, and apply them.

For starters, BNPL apps must clearly outline their communications policy and state the information their employees will ask for. In most cases, BNPL apps do not need sensitive information, so anyone asking for login IDs or OTP codes should be a red flag.

Educating consumers about the possible ways their account might suffer a compromise is also a good way to keep them alert.

 

Trojans and API endpoint exploits

Over the past few years, ransomware attackers have used a novel attack vector. They clone existing popular apps and release them with malicious code embedded in them. Given the app’s popularity, consumers download malicious versions and divulge sensitive data.

BNPL has faced significant uptake because of the ease of onboarding and the short time to first purchase. In such environments, users and existing customers have little opportunity to notice a wrong environment. While app redesigns are not a solution, security teams have several options available.

Installing RASP protection including anti-debugging, tampering, and reversing should be standard practice. In addition, teams must also implement binary patching prevention, app resigning, and other dynamic protection that secures the user experience every step of the way.

API endpoints are another vulnerable part of the app experience. Given the sensitivity of the data BNPL apps hold, security teams must include data encryption for at-rest data, string, and resource encryption. Installing root detection and prevention is also a great way to further enhance app security.

 

No revolution without security

BNPL has been hailed as a revolution in consumer finance and fintech. However, apps cannot revolutionize consumer purchases without guaranteeing top-notch security first. The methods in this article are just a few of several ways app security teams can protect their users and themselves from ransomware attacks.

 

About the Author

Jeff Broth is a business writer and advisor. Consulted for SMB owners and entrepreneurs for 9 years now. Mainly covering Data, human resources, and emerging fintech trends.

Click here for more IT Briefcase content!

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more