Hackers infect e-commerce sites by compromising their advertising partner

Magecart strikes again, one of the most notorious hacking groups specializes in stealing credit card details from poorly-secured e-commerce websites.

According to security researchers from RiskIQ and Trend Micro, cybercriminals of a new subgroup of Ma… Continue reading Hackers infect e-commerce sites by compromising their advertising partner

Thieves make off with shoppers’ credit card numbers after hacking apparel site for four months

Shoppers who placed an order with discountmugs.com during a four-month period last year are receiving a worrying notification from the online apparel store. Apparently, hackers injected card skimming code into the company’s website, then stole en… Continue reading Thieves make off with shoppers’ credit card numbers after hacking apparel site for four months

BevMo leaks credit card data (including CVVs) of 15,000 customers

American alcohol retailer BevMo has suffered a breach that leaked credit card data, including security codes, belonging to 15,000 customers. A privately-held corporation based in Concord, California, BevMo sells mostly alcoholic beverages. The company … Continue reading BevMo leaks credit card data (including CVVs) of 15,000 customers

Caribou Coffee reports data breach including payment information at 265 stores

American coffee seller Caribou Coffee recently suffered a breach exposing customer payment data at 265 U.S. stores for roughly three months, according to a notice posted to the company’s website. The retailer says an outsider had unauthorized access to point-of-sale systems at affected locations between Aug. 28 and and Dec. 3, someone had unauthorized access to its point of sale systems at affected stores. Hackers may have accessed customer names, payment card numbers, expiration dates and security codes. The company says payments made through its rewards program were not affected. Caribou says that it detected “unusual activity” on its network on Nov. 28, which prompted it to hire Mandiant, a cybersecurity incident response company owned by FireEye. Mandiant identified the issue within two days, the notice says, although customers may have been affected through Dec. 3. Caribou says it’s working to beef up its network security and its payment system in order to better protect customer information. […]

The post Caribou Coffee reports data breach including payment information at 265 stores appeared first on CyberScoop.

Continue reading Caribou Coffee reports data breach including payment information at 265 stores

Is taking CC info in plain HTML elements, but using a library like Stripe to tokenize PCI compliant?

I am building a site which will accept payments. I will be processing payments with either Stripe or Square. Stripe now has Stripe Elements, and Square has Square Payment Form. I have tried Square Payment form but it’s hard t… Continue reading Is taking CC info in plain HTML elements, but using a library like Stripe to tokenize PCI compliant?