Any number of ways from physical access to a terminal, back office server, head office PC, plugging their own lappy into a live LAN socket in store (or weakly password-protected in-store Wi-Fi), infected website payload downloaded on the back office PC by staff at lunchtime etc

Mix together electronic payment processing and (often, but not necessarily in this case) elderly POS terminals running embedded/outdated/ne'er patched OSes and it's not long until something stinky cooks up.

