actually, he is not..... think of it as an sql injection with a pos, it is possible, not necessarily how it was done here but also there is no card to retrieve the data, they steal the pos after using the card with the encoded virus to make the machine itself store data locally.