A recent indictment against a notorious group of Russian and Ukrainian hackers shows just how damaging this type of attack can be. The indictment provides a long list of companies that have suffered costly data breaches where the root cause has proven to be a SQL injection. An attacker can use SQL injection to upload malware into the database system and then have that system send out the malware to all the POS endpoints. The recent Target, Neiman Marcus and Michaels breaches also might stem from SQL injection attacks of some sort.”]

