Hackers stole payment data from Costway’s website and other compromised Magento 1 websites using e-commerce credit-card skimmers.
One skimmer injects fake forms into an affected website while the other one collects credit-card details. Fortunately, this exploit only runs on outdated Magento 1 e-commerce software. Magento developers urged every customer to update to their latest software version.
“A large number of Magento 1 sites have been hacked but yet are not necessarily being monetized. […] Other threat actors that want access will undoubtedly attempt to inject their own malicious code. When that happens, we see criminals trying to access the same resources and sometimes fighting with one another.”Malwarebytes
Researchers at Malwarebytes identified French, UK, German, and Spanish Costway portals affected by these skimmers. The potential risk is massive, as only the French portal had over 180,000 visitors in December. The website’s payment form was collecting every buyer’s payment details.
Check the source.
- Users of popular crypto app Maiar are targetted by SMiShingMaiar is a digital crypto wallet and global payments app that allows users to exchange and securely store money […]
- PHOBOS Ransomware Attack Hits Romanian Hospital on July 22A ransomware attack targeted Witting Clinical Hospital in Bucharest. Hackers took control of the healthcare provider’s servers, encrypted the […]
- 740 Ransomware Victims Listed On Data Leak Sites in Q2 2021, New Report ShowsA new report from Digital Shadow highlights the worrying information that the number of ransomware victims named on data […]
- Kaseya Gets Universal Decryptor for REvil RansomwareThe decryptor vendor will work closely with customers affected by this July’s outbreak of ransomware attacks to help recover […]
- Possibly the Highest Ransomware Payment Ever: CNA reportedly paid $40 million to hackersOne of the biggest US insurance companies, CNA, paid a ransom worth $40 million to attackers after a massive […]