Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Magecart Victim? You Won’t Even Know Unless You Do This
Articles

Magecart Victim? You Won’t Even Know Unless You Do This

ISBuzz TeamBy ISBuzz TeamSeptember 30, 2019Updated:July 13, 20203 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

If someone at your company were to tell you that a critical database was left unprotected for the past six months, exposing data of millions of your customers, you’d likely be outraged. In 2019 forgoing basic server security is completely unacceptable.

But then we look at the growing wave of Magecart attacks — malicious credit card skimming code that’s typically injected via compromised third-party tools — and learn about data breaches that took two, five, or even six months to be detected. Such was the case of the recently disclosed data breach at the National Baseball Hall of Fame website, which remained active and undetected between November 15, 2018 and May 14, 2019. While we still don’t know how many customers had their credit card information stolen in this attack, other Magecart attacks on Ticketmaster resulted in 40,000 stolen credit cards and took 5 months to be detected. And more recently, the attacks on Amerisleep and MyPillow also remained undetected for 2 months.

The picture gets much grimmer when we consider that a single Magecart attack typically breaches not one but hundreds or even thousands of businesses at once. The biggest to date infected 17,000 websites in one go. Unlike a first-party data breach, which often requires attackers to infiltrate a database, third-party data breaches like Magecart originate from attackers going after the enterprise’s smaller, less secure providers which are the weakest link in the web supply chain. This makes attackers’ lives arguably easier, especially when we again consider this huge discrepancy between server-side and client-side security.

There clearly hasn’t been enough awareness and investment in client-side security, especially in preventing Magecart attacks. Now that we saw some big headlines on the British Airways $230 million GDPR fine following the 2018 Magecart attack, hopefully, the C-Suite has become aware of the real damages of a client-side data breach. Now, a further push must be made for spreading awareness on the most suitable approaches to mitigate Magecart and other web supply chain attacks.

It’s undeniable that these attacks exploit the Achilles heel of web security: zero visibility over what’s happening on the client-side of web applications. For each day that a Magecart attack flies under the radar, potentially thousands of new customers have their credit cards stolen. To gain full visibility and greatly minimize this attack surface, businesses must address webpage monitoring solutions. These enable detecting every piece of malicious client-side code in real-time, all the while triggering countermeasures to block the attack at its inception.

And the bottom line is quite simple: every company with websites that process credit card payments and which isn’t monitoring webpages in real time is potentially being breached by a Magecart attack as we speak. And worse, all customers whose credit cards are being stolen won’t be notified until it’s too late. If nobody at your company knows what’s going on with the client-side of your website, then you probably have the right to be filled with outrage and take action while there’s time.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}