eCommerce Retailers Experiencing Active Security Leaks
September 05, 2019
Share this

Research conducted by Aite Group uncovered more than 80 global eCommerce sites that were actively being compromised by Magecart groups, according to a new report, In Plain Sight II: On the Trail of Magecart commissioned by Arxan Technologies.

In 2018, Magecart groups made headlines as the threat actors responsible for high-profile mega-breaches of global brands including Ticketmaster, Forbes, British Airways, Newegg and more. "Magecart" is an umbrella term given to multiple threat groups that use credit card skimming technology to infect eCommerce platforms and websites with the goal of stealing personal and financial information — without being detected for months or even years at a time. Virtual credit card skimmers, also known as formjacking, are inserted into a web application, often the shopping cart, and are used to steal credit cards to sell on the black market and for shipping scams to traffic goods purchased with stolen cards.

"Once again we're disappointed in what the research uncovered: the systemic lack of web-app protection being used by eCommerce websites and the inability of network and endpoint security solutions to completely protect consumers against this pervasive threat," says Aaron Lint, Chief Scientist and VP of Research, Arxan. "The push toward a modern user experience creates a lucrative attack surface inside the web content delivered via browser and mobile. Any interface which takes user input becomes a target for exfiltration. Additionally, the widespread use of third-party components has created a supply chain where an attacker can easily compromise thousands of sites with a mere few lines of code."

As organizations continue to rely on revenue from eCommerce – estimates project the global market to hit more than $3.5 trillion in 20191 – the potential financial impact of Magecart is dire. The fallout from digital skimming breaches in 2018 cost organizations hundreds of millions of dollars in government penalties alone. Making matters worse, an estimated 20 percent of websites hit by Magecart become reinfected within five days of remediating the original problem. It's a bleak picture for an industry about to embark on the busiest shopping season of the year.

"The threat of formjacking is a widespread and growing problem. Because so many web applications are lacking in-app protection, adversaries are able to easily debug and read a web app's JavaScript or HTML5 in plain text. Once the web app code is understood, malicious Javascript is then inserted into the web pages of target servers that delivers the web checkout form. Once weaponized, these credential pages will simultaneously send a consumer's credit card information to an off-site server under the control of the Magecart group while also allowing the compromised site to process the credit card so the consumer and the organization is unaware of the theft," says Alissa Knight, cybersecurity analyst for Aite Group and author of the In Plain Sight series of research. "It's important to adopt solutions that implement multiple layers of security, not just obfuscation, such as detection of code tampering and analysis, active response that shuts a browser down upon detection of formjacking, along with threat detection and real-time alerting and response."

To conduct this research, Knight used a source code search engine that scoured the web for obfuscated JavaScript that she found in repeating patterns of previously published Magecart breaches. Just 2.5 hours of initial research led to the discovery of over 80 compromised eCommerce sites globally that were actively sending credit card numbers to off-site servers under the control of the Magecart groups.

The research showed that:

■ The most common similarity across the 80 sites was the use of Magento, all of which are running old versions that are vulnerable to an unauthenticated upload and remote code execution vulnerability that has published exploits available for it.

■ 100 percent of the 80 sites discovered had no in-app protection implemented, such as tamper detection and code obfuscation.

■ 25 percent of the sites discovered were large, reputable brands in the motorsports industry and luxury apparel.

To combat this growing threat, here are some steps that retailers and eCommerce organizations can take to protect their customers:

■ Update or patch eCommerce platforms to the latest version.

■ Audit web code to ensure websites, including any third party apps, have not been compromised.

■ Implement a security solution that can provide alerts when suspicious activity targets web application code.

Share this

The Latest

February 27, 2020

The Cloud Performance Benchmark from ThousandEyes compares global network performance and connectivity differences between the five major public cloud providers — Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, Alibaba Cloud and IBM Cloud — proving that, when it comes to performance, not all clouds are created equal ...

February 26, 2020

For the past 10 years, the majority of CIOs have had a transformational focus (currently 42%), however, this year, there is strong momentum in CIOs taking on more strategic responsibilities (40%), according to the 2020 State of the CIO research from IDG's CIO ...

February 25, 2020
A widening gap between IT resources and the demands of managing the increasing scale and complexity of enterprise cloud ecosystems is evident, according to <span style="font-style: italic;">Top challenges for CIOs on the road to the AI-driven autonomous cloud</span>, a new report based on a global survey of 800 CIOs conducted by Vanson Bourne and commissioned by Dynatrace ...
February 24, 2020

The tech world may be falling in love with artificial intelligence and automation, but when it comes to managing critical assets, old school tools like spreadsheets are still in common use. A new survey by Ivanti illustrates how these legacy tools are forcing IT to waste valuable time analyzing assets due to incomplete data ...

February 20, 2020

Over 70% of C-Suite decision makers believe business innovation and staff retention are driven by improved visibility into network and application performance, according to Rethink Possible: Visibility and Network Performance – The Pillars of Business Success, a survey
conducted by Riverbed ...

February 19, 2020

Modern enterprises rely upon their IT departments to deliver a seamless digital customer experience. Performance and availability are the foundational stepping stones to delivering that customer experience. Along those lines, this month we released a new research study titled the IT Downtime Detection and Mitigation Report that contains recommendations on how to best prevent, detect or mitigate brownouts and outages, given the context of today’s IT transformation trends ...

February 18, 2020

While Application Performance Management (APM) has become mainstream, with a majority of tech pros using APM tools regularly, there's work to be done to move beyond troubleshooting ...

February 13, 2020

Over the last few decades, IT departments have decreased budgets in part because of recession. As a result, they have are being asked to do more with less. The increase in work has amplified the need for automation ...

February 12, 2020

Many variables must align for optimum APM, and security is certainly among them. I offer the following APM predictions for 2020, which revolve around the reality that we will definitely begin to see much deeper integration of WAN technology on the security front. Look for this integration to take shape in the following ways ...

February 11, 2020

When it comes to growing a successful company, research shows it isn't about getting the most out of employees, but delivering an experience that empowers them to be and do their best. And according to Priming a New Era of Digital Wellness, a new study conducted by Quartz Insights in partnership with Citrix Systems, technology is the secret to doing so ...