How to Prevent Cryptojacking Attacks When You Deliver Your Own Orders

Learning center series

How to Prevent Cryptojacking Attacks When You Deliver Your Own Orders

Prevent Cryptojacking attack

Most malware wants your money or your data. Cryptojacking wants something stranger: your electricity, your processor cycles and your cloud bill. Someone else’s mining software runs quietly on your machines, and you pay for it in slow terminals, hot laptops, dead phone batteries and a power bill nobody can explain.

For a business that packs and delivers its own orders, that lands in an unusually bad place. The morning rush is the point in the day when every machine matters at once: the terminal taking phone orders, the laptop building the route, the printer spitting labels, the phone in the driver’s hand showing the next stop. A miner does not have to break anything to hurt you. It only has to make all of it slower on the one morning you have forty drops and a cold chain to protect.

This guide is the prevention side of the problem: the controls that stop mining code getting a foothold in the first place. If your real question is whether something is already running on a machine right now, the sibling to this post walks through the symptoms and the checks: how to detect cryptojacking on dispatch, POS and driver devices. Start there if a machine has started behaving oddly this week.

The Bottom Line

  • Cryptojacking is theft of compute, not data. The attacker’s payout is small and your cost is large: Sysdig calculated victims lose about $53 for every $1 the miner earns.
  • Small operations are not too small to be hit. The attacks are opportunistic and automated. They scan for an unpatched thing and take whatever they find.
  • Patching is the single highest-value control. Verizon’s 2026 DBIR found exploited vulnerabilities overtook stolen credentials as the leading way in.
  • Cloud and account access is where the bill gets frightening. A compromised cloud key can be mining within minutes, and the charges are yours to pay.
  • Driver phones and public Wi-Fi are part of your attack surface. They are business machines, whoever owns them.
  • Prevention is layered, not a single product. Updates, an ad and script blocker, endpoint protection, tight accounts and staff who know what a bad attachment looks like.

Lower your delivery costs by 23%

"Cut our delivery costs by 30% while improving service"
— Gabriel Gibson, Flamingo Estate

How we reduce costs:

  • No delivery vehicle expenses
  • Optimized local routes
  • Pay-per-delivery model
  • Average 23% delivery cost reduction

What a cryptojacking attack costs a delivery operation

Cryptojacking is the unauthorised use of your computers to mine cryptocurrency. The attacker installs mining code, or loads it in a browser tab, and your hardware does the work of solving the mathematical puzzles that earn coins. The coins go to them. The costs stay with you.

The lopsidedness is the part most owners underestimate. Sysdig’s threat research team traced one cloud-mining campaign in detail and found that generating roughly $8,100 in cryptocurrency had cost the victims more than $430,000 in cloud charges: a $53 loss for every $1 the attacker gained. Mining is a spectacularly inefficient way to make money, which is exactly why criminals prefer to do it on someone else’s equipment.

On the ground, in a business with vans going out at seven, the costs show up as:

  • Slow machines at the worst hour. A terminal that takes eight seconds to load an order instead of one is a queue of phone calls you did not answer.
  • Hardware dying early. Mining runs processors at full load for hours. Fans, batteries and thermal paste were not specified for that, and tablets in vans are already living hard lives.
  • Energy you are buying for a stranger. A handful of machines pinned at 100% around the clock shows up on the electricity bill.
  • A cloud invoice with no explanation. If the mining is happening in a cloud account, the charge is metered and automatic.
  • An open door you have not closed. This is the one that should worry you most. Whoever installed a miner had enough access to install anything. The same foothold resells easily to someone with worse plans.

And volume is not the reassuring part. SonicWall’s threat researchers logged 332.3 million cryptojacking hits in the first half of 2023, a 399% rise on the same period the year before, with retail volume more than doubling. These campaigns are automated sweeps. Nobody picked your bakery; a scanner found a machine and moved in.

How cryptojacking gets onto dispatch laptops, POS terminals and driver phones

Prevention is easier when you know the doors. In practice there are five that matter for a small operation.

Malicious email attachments and links are the classic route, and the one aimed squarely at you. A purchase order from a “new wholesale customer”, an invoice from a “supplier”, a delivery exception notice: order-taking inboxes open attachments from strangers all day, which is what makes them a good target.

Compromised websites and malvertising need no install at all. A few lines of JavaScript on a page, sometimes in an ad served onto an otherwise legitimate site, mine for as long as the tab is open. Back-office machines that sit on a supplier portal all day are ideal hosts.

Unpatched software on anything internet-facing is the next door. Routers, firewalls, the old PC running the label printer, a server nobody logs into. The 2026 Verizon Data Breach Investigations Report found exploitation of vulnerabilities had overtaken stolen credentials as the leading initial access route, with unpatched edge devices behind 29% of breaches.

Stolen credentials and exposed cloud keys are the fastest route of all. If you run anything in a cloud account, a leaked key is the fast lane. Amazon’s security team documented a 2025 campaign that went from compromised credentials to running miners in under ten minutes.

Free software and browser extensions close the list. The route planner someone downloaded from a search ad, the PDF converter, the extension that promised to fix something. Installers bundled with miners are a long-running staple.

Patch the software your delivery day depends on

If you only do one thing from this guide, do this one. Updates are unglamorous, they land at inconvenient times, and they close the hole most attacks walk through.

Make a list (an actual list, on paper is fine) of everything that touches your operation and connects to a network. Order-taking computers. The POS terminal. The router and any Wi-Fi access points. Label and receipt printers. Phones and tablets used for deliveries. The accounting machine. Cameras. Then, for each one, answer two questions: does it update automatically, and if not, who updates it and when?

A few practical rules:

  • Turn on automatic updates everywhere they exist, and schedule restarts for after the last run rather than mid-morning.
  • Treat the router and firewall as first-class machines. They are the most exposed things you own and the most often forgotten. Log in, check the firmware version, change the default admin password while you are there.
  • Replace what can no longer be patched. A POS terminal on an operating system that stopped receiving security updates is not a cost saving.
  • Put a repeating reminder in the calendar. First Monday of the month, twenty minutes, walk the list.

Block browser-based cryptomining before it starts

In-browser mining is the easiest variant to stop, because it never gets installed. Three layers handle almost all of it.

A reputable ad blocker or script blocker on every browser your staff use cuts out malvertising, which is the main delivery mechanism for drive-by mining. Most of the well-known blockers now ship with dedicated anti-cryptomining filter lists you only need to switch on.

Mining-specific browser blockers add a second layer that works on the mining scripts themselves rather than the ads carrying them. Install them from the official browser store and nowhere else.

Fewer extensions overall is a control in its own right. Audit what is installed on the shared back-office machine once a quarter and remove anything nobody can name a use for. Extensions change hands, and a useful tool bought by the wrong owner becomes a miner in an update.

Keep browsers themselves current, and set them to update on their own. Modern browsers also throttle background tabs, which limits how much a hidden tab can steal, but only on a version recent enough to have the feature.

Stop cloud cryptojacking from running up your bill

If any part of your operation runs in the cloud (a hosted ordering system, a server for your website, storage for your customer list), this section is the one with the four-figure downside. On your own hardware, mining costs you electricity. In a cloud account, it costs you whatever the meter says, and the meter moves quickly.

  • Turn on multi-factor authentication for every account with cloud access. Not just the owner’s. The bookkeeper’s too.
  • Stop reusing passwords across business accounts. A password manager makes one strong credential per account practical, which matters because stolen credentials remain one of the two main ways attackers get in.
  • Never leave keys in shared places. Access keys pasted into a chat thread, a shared doc or a code repository get found by automated scanners within hours.
  • Give each account only what it needs. A login that can read order data does not need permission to spin up servers.
  • Set a billing alert. A hard spending alarm at a number that would surprise you is the cheapest cryptojacking detector in existence, and it works while you sleep.
  • Delete what you stopped using. The test environment from two years ago is unmonitored and still billable.

Protect driver phones and the machines that leave the building

Devices on the road are business devices, whether the business bought them or the driver did. They carry your customer addresses and log into your systems, and they spend the day on networks you do not control.

Require a screen lock and a current operating system on any phone used for deliveries; most mobile mining arrives through sideloaded apps, so keep installs to the official app stores. Ask drivers to avoid open public Wi-Fi at cafés and depots for anything work-related. Mobile data is safer, and a VPN is the right answer when Wi-Fi is unavoidable. And keep a short, boring rule in place for lost or stolen phones: it gets reported the same day, and the accounts it was signed into get their passwords changed.

Endpoint protection belongs on everything that can run it. Reputable security software catches known mining families and the droppers that install them, and it is the layer that keeps working when someone clicks the thing they should not have clicked. Several VPN providers now bundle it in. NordVPN’s malware scanner checks downloads before they open, which suits a device that spends its day on other people’s networks.

Make your staff the layer that stops the attachment

Human behaviour was involved in 62% of the breaches in Verizon’s 2026 report, and the fix is not lecturing people. It is giving them a short, specific set of things to check. Most of what your team needs fits on one page by the till:

  • Unexpected attachment from an unknown sender: do not open it. Phone the number on the company’s website, not the number in the email.
  • An invoice or order that arrives with urgency attached deserves more scrutiny, not less. Pressure is a technique.
  • Nobody installs software on a business machine without asking. One rule, no exceptions, including the owner.
  • Report a slow or hot machine instead of living with it. Most miners are found by someone who mentioned their laptop was noisy.

Security awareness overlaps neatly with the other losses a small operation carries. The instinct that makes someone question a fake supplier invoice is the same one that spots a customer leaving without paying or notices the till patterns behind employee theft. It is one habit of scepticism, applied in a few different places.

How to tell whether a miner already got through

Prevention is worth more than cure here, but no stack is perfect, so know the shape of the failure. The signals are unglamorous: machines running hot and loud with nothing open, processors sitting at high usage when the shop is closed, batteries on delivery phones dying by noon, browser tabs that make the fan spin up, a cloud or power bill that moved for no reason you can name.

The full walkthrough lives in the detection guide for dispatch, POS and driver devices: checking processor usage properly, finding the process, the tools that identify mining traffic, and what to do about the account access the attacker probably still has. If two or three of those signals showed up in the same week, start there rather than here.

Your first hour after finding a miner

Speed matters less than order of operations. Disconnect the affected machine from the network but leave it powered on if you can, so a technician can see what is running. Change the passwords for every account that machine was signed into, from a different machine. Run a full scan with your security software, and be honest about whether a clean rebuild is faster than a cleanup. For a terminal with nothing unique on it, reinstalling is usually the cheaper afternoon.

Then check the cloud billing and any account with payment details attached, because that is where an unnoticed miner turns into real money. And treat the incident as what it was: a hole big enough for someone to install software. Find it, close it, and assume anything on that machine was readable.

Frequently asked questions

Is cryptojacking illegal?

Yes. Using someone else’s computing resources to mine cryptocurrency without permission is unauthorised access to a computer system in most jurisdictions, including under the US Computer Fraud and Abuse Act. That it steals electricity rather than data does not change its status.

Can a cryptojacking attack steal my customer data?

Not directly. Mining code mines. But the access needed to install it is the same access needed to take anything else on the machine, and cryptominers are frequently dropped by the same toolkits used for data theft and ransomware. Treat a mining infection as a full compromise.

Does antivirus software prevent cryptojacking on its own?

It prevents a good share of it and will not catch everything, particularly browser-based mining and newly written variants. It is one layer of several: updates, a script blocker, tight account permissions and cautious staff are the others.

Are phones and tablets at risk, or just computers?

Both. Mobile mining is less profitable per device, so attackers compensate with volume through sideloaded apps and malicious ad networks. On a delivery phone the symptom is usually brutal battery drain and a device too hot to hold.

How much does cryptojacking prevention cost a small business?

Less than most owners assume. The highest-value controls are free: automatic updates, multi-factor authentication, an ad blocker, a billing alert, a rule about installing software. Endpoint protection for a handful of machines is a modest monthly cost, and it is the one layer to spend money on.

About the Author

Picture of Oguzhan Uyar
Oguzhan Uyar
CEO of Metrobi. Metrobi helps you find reliable drivers with clear pricing, tracking, and route optimization. With an entrepreneurial spirit, Oguzhan has been transforming local delivery logistics since 2019.
Related posts
In this article
Cryptojacking
Learning center articles
Other Learning Center Subjects