Skip to main content
Application Security padlock icon
Last Updated Jun 05, 2020 — Application Security expert

In Plain Sight II: On the Trail of Magecart

Application Security

On the surface, the breaches that impacted British Airways, Ticketmaster and Forbes seem like any other cyberattack: a bad actor finds a security hole and exploits it. And while the headlines may not appear unique, the fact that Magecart style attacks continue to succeed at breaching the websites of global companies without being detected is costing millions of dollars in fraudulent credit card charges and government penalties.

New research conducted by advisory firm Aite Group revealed that 100% of the eCommerce  websites examined were not protected — making them easy prey for Magecart attacks. Even more startling is the fact that it took only 2.5 hours of research to uncover the 80 compromised sites. Among the other notable findings:

  • All of the compromised websites use an outdated version of Magento which is vulnerable to formjacking and digital card skimming
  • None of the websites used appropriate in-app protection capabilities such as code obfuscation and tamper detection
  • 25% of the sites were large brands in motorsports and luxury retail

Download the full report to learn more about the methods and techniques Magecart groups use to conduct digital card skimming and formjacking, and the security measures you can deploy to protect your website and your customers.

 

More from the Blog

View more
Jan 18, 2022

Be aware or beware: Easily insert security into your mobile apps

Application Security
COVID-19 has quickly pushed companies over the technological tipping p ...
Read More
Dec 23, 2021

Using machine learning to detect malicious packages

Application Security
Staying up to date with new technology in today’s advanced digital age ...
Read More
Dec 17, 2021

Log4j: Not the Vulnerability We Want, and Not the Vulnerability We Need

Application Security
Log4j is the reminder we didn’t need: the reminder that vulnerabilitie ...
Read More
Apr 29, 2021

Why better security means better products

Application Security
Over the past 15 years, businesses have learned a lot about the value ...
Read More
Contact Us