Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Your Customer Data at Stake: The Latest Magento Shoplift Flaw and How You Can Stay Protected
Articles

Your Customer Data at Stake: The Latest Magento Shoplift Flaw and How You Can Stay Protected

ISBuzz TeamBy ISBuzz TeamMay 8, 20155 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Latest Magento Shoplift Flaw and How You Can Stay Protected
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

What you need to know right now to protect your site and customers from the Magento flaw

Imagine you owned a grocery store and someone simply walked into it, appointed himself manager and then used his newfound authority to help himself to customer credit card information and even change the prices of items. It’s such a seemingly unrealistic situation it borders on unfathomable, right? And yet, nearly 100,000 stores all over the world found themselves facing this exact threat this week.

Magento is the number one open-source content management system for e-commerce websites. That means that when a vulnerability was discovered in community and enterprise editions of Magento, almost 100,000 e-commerce websites were immediately at risk, which put the personal information of millions of consumers at risk at well. Here’s everything you need to know about the Magento flaw in order to protect your website and your customers.

Magento vulnerability details

What’s being called the Magento flaw or vulnerability is a remote-code execution hole in enterprise and community versions of the Magento content management system. This vulnerability is actually a series of vulnerabilities that give an attacker the ability to execute PHP code on the web server. This allows the attacker to bypass security, create a new administrator account, and seize control of not just the online store but its complete database, including the personal and financial information of customers.

While this vulnerability could potentially be exploited by any attacker with the necessary skills, so far there seems to be a couple of specific group of attackers taking advantage of it. If you suspect your website has been compromised, check for usernames default manager or vpwq, as these are the names security groups have seen cropping up in the attacks. You could also check for access from IP addresses 62.76.177.179 and 185.22.232.218.

Full access and full control

Because the Magento vulnerability allows attackers to create new administrator accounts, it gives those attackers all the same powers an administrator would have. And since the type of people who quickly take advantage of a newly-discovered vulnerability aren’t the type of people who would pop into your website just to change the name of your store to Pee Pants Enterprises and have themselves a little laugh, this is bad.

By exploiting the Magento vulnerability, attackers are able to dump database content to obtain credit card data and customers’ personal information like phone numbers, addresses and emails. Having all of that data properly encrypted is a good security measure, but attackers may still be able to insert a script that steals that information while it’s briefly being processed prior to encryption. The damage that could possibly be done from this attack may not be done immediately.

Attackers are also able to tinker with other admin settings, such as changing the prices of items in the online store, and could possibly set up malware to infect customers’ computers.

By the numbers

Magento is owned by ecommerce giant eBay, and their engineers were first informed of the vulnerability in January. They acted on the information and released a patch in February. However, as of last week, over 98,000 ecommerce sites still hadn’t installed it.

According to internet security firm Incapsula, the attack attempts began last Monday, with fewer than 250 attempted attacks on sites under the protection of Incapsula. According to Incapsula reports, the action ramped up on Tuesday and reached a peak last Sunday, with almost 1500 attempts on Incapsula-protected sites that day. Incapsula state that the attacks seem to be originating from Russia and China.

Incapsula report

Number of attacks per date (source + Hi-res: Incapsula report)

What ecommerce sites need to do NOW

If you have a website utilizing the community or enterprise editions of the Magento CMS, you need to be on the Magento downloads page downloading patch SUPEE-5344 right now. If you haven’t done it, go do it.

Furthermore, whether your ecommerce site uses Magento or any other type of CMS, for the sake of your website and your valued customers, you need to be looking into a Web Application Firewall, preferably a SaaS WAF. Even if you’re not affected by this vulnerability, you could be affected by the next one. A good WAF will protect you from a wide range of security threats, including DDoS attacks, by dictating the way users, both humans and bots, are allowed to interact with your website.

With our increasingly online world, the surreal becomes more real every day, and unfathomable attacks on businesses are becoming all too fathomable. The best defense will always be a good offense. Protect your website before it becomes time to scramble for a patch.

By Benjamin Stone writer and technology enthusiast

Benjamin StoneBIO : Benjamin is a seasoned writer and technology enthusiast. He has written various articles on the topic of cyber security and continues to research the latest state of the art tools for tackling cyber scares. In his spare time Benjamin enjoys reading finance magazines and enjoying outdoor sporting activities.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}