What’s the matter?
Security researchers from Aite Group and Arxan Technologies have discovered that Magecart attackers have compromised over 80 eCommerce websites.
A brief overview
Researchers from Aite Group analyzed e-commerce websites and within 2.5 hours of research they found out at least 80 e-commerce sites that were compromised by Magecart attackers.
The research revealed that 100% of the analyzed eCommerce websites were not protected and were vulnerable to digital card skimming and formjacking attacks.
Researchers reported their findings to federal law enforcement and are notifying all the impacted e-commerce organizations. The compromised e-commerce sites belong to various countries such as the United States, Canada, Europe, Latin America, and Asia. However, the names of the victim sites were not revealed.
“To conduct this research, Aite Group used a source code search engine that scoured the web for obfuscated JavaScript that was found in repeating patterns of previously published Magecart breaches on pastebin.com.” read the report.
Key findings
“The attacker has the purchased items shipped to their merchandise mules. To recruit merchandise mules, the attacker posts jobs that offer people the ability to work from home and earn large sums of money to receive and reship merchandise purchased with the stolen credit card numbers,” wrote the researchers in the report.
Recommendations
Publisher