Newegg users’ credit card info breached in month-long data hack

The culprits are the same group behind the British Airways and Ticketmaster breaches

Online hardware retailer Newegg has suffered a large-scale payment data breach, which exposed customers' credit card details to hackers for an entire month.

The attackers look to be the same as those behind the British Airways and Ticketmaster UK breaches earlier this month, with researchers referring to the group as Magecart.

"We can assume this attack claimed a massive number of victims," said threat management firm RiskIQ, which exposed the breach along with the security research company Volexity.

The full scope of the attack is not yet known, although Newegg has sent an email to customers informing them of the hack, and that the company is "conducting extensive research" to determine what data was accessed. It promised an FAQ on the breach by 21 September.

IT Pro has contacted Newegg for comment.

The hackers injected 15 lines of Javascript to Newegg's payment page, which skimmed credit card data on desktop and mobile between 14 August and 18 September, when the company eventually shut down the code.

The base code behind the attack was the same as that used in the British Airways breach, with only minor changes made to the form needed to serialise payment information, and the server to send that information to.

Credit: RiskIQ

According to RiskIQ, which also uncovered the code behind the British Airways breach, the Magecart hackers registered a domain neweggstats.com through Namecheap. On 14 August, the attackers changed the destination of the domain to a drop server, which received the skimmed credit card information.

"While some Magecart groups still target smaller shops, the subgroup responsible for the attacks against Newegg and British Airways is particularly audacious," said RiskIQ's Yonathan Klijnsma, noting that that the highly targeted attacks use code that "seamlessly integrate into their targets' websites."

Newegg has close to 50 million monthly visitors, and even if a small percentage of that makes purchases, the amount of skimmed credit card information over several weeks could be substantial. The pattern of Magecart attacks in the last month also suggests the approach taken by the attackers is becoming increasingly popular. 

"Historically, threat actors deploying Magecart have targeted small businesses and so stayed largely under the radar," security expert Davey Winder told IT Pro.

"There appears to have been a shift to more audacious attacks, with less concern over stealth, and given the success of these exploits there's no reason to assume they will cease any time soon."

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

Biden nominees highlight tough cyber security challenges
cyber security

Biden nominees highlight tough cyber security challenges

20 Jan 2021
Report: Security staff excluded from app development
cyber security

Report: Security staff excluded from app development

20 Jan 2021
Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

20 Jan 2021
SolarWinds hackers hit Malwarebytes through Microsoft exploit
hacking

SolarWinds hackers hit Malwarebytes through Microsoft exploit

20 Jan 2021

Most Popular

IT retailer faces €10.4m GDPR fine for employee surveillance
General Data Protection Regulation (GDPR)

IT retailer faces €10.4m GDPR fine for employee surveillance

18 Jan 2021
Citrix buys Slack competitor Wrike in record $2.25bn deal
collaboration

Citrix buys Slack competitor Wrike in record $2.25bn deal

19 Jan 2021
Should IT departments call time on WhatsApp?
communications

Should IT departments call time on WhatsApp?

15 Jan 2021