magecart

Latest

  • stack of multicolored credit cards, close up view with selective focus

    Hackers are hiding virtual credit card skimmers in image file metadata

    by 
    Marc DeAngelis
    Marc DeAngelis
    06.26.2020

    Sites using WooCommerce are being targeted by hackers as a way to steal credit card information.

  • Charles Sykes/AP Images for Macy's

    Macy's says its website leaked credit card info to hackers for a week

    by 
    Jon Fingas
    Jon Fingas
    11.19.2019

    The constant stream of card skimming hacks just claimed a particularly high-profile target. Macy's has warned customers that intruders slipped code (believed to be JavaScript) into two pages on its website on October 7th, letting them collect data from shoppers that included names, addresses and payment info. Macy's shut down the attack soon after discovering it on October 15th, but it's unclear just how many people were affected. The company told Bleeping Computer that a "small number" of people were victims, and that it had both implemented "additional security measures" and offered free credit monitoring.

  • Card skimming hack targets 201 campus stores in North America

    by 
    Jon Fingas
    Jon Fingas
    05.06.2019

    The infamous Magecart card skimming hack has been used to make life miserable for college students. Trend Micro has discovered that a hacking group, currently nicknamed Mirrorthief, relied on the scripting technique to steal card data from 201 online campus stores across the US and Canada on April 14th. The team slipped its scripts into the checkout pages of the sites (all created by a common developer, PrismRBS) to harvest full card details, names, addresses and phone numbers. The number of people affected by the heist isn't yet clear.

  • Reuters/Mario Anzuoni

    Newegg fell victim to month-long card skimming hack

    by 
    Jon Fingas
    Jon Fingas
    09.19.2018

    It's not just British companies succumbing to large-scale payment data breaches in recent weeks. RiskIQ and Volexity have discovered that hackers inserted Magecart card skimming code into Newegg's payment page between August 14th and September 18th, intercepting credit card data and sending it to a server with a similar-looking domain.

  • Reuters/Hannah McKay

    British Airways hackers used same tools behind Ticketmaster breach

    by 
    Jon Fingas
    Jon Fingas
    09.11.2018

    The British Airways web hack wasn't an isolated incident. Analysts at RiskIQ have reported that the breach was likely perpetrated by Magecart, the same criminal enterprise that infiltrated Ticketmaster UK. In both cases, the culprits used similar virtual card skimming JavaScript to swipe data from payment forms. For the British Airways attack, it was just a matter of customizing the scripts and targeting the company directly instead of going through compromised third-party customers.