Digital scammers have included malicious Magecart code on more than 2 million websites, according to new research that demonstrates how hackers exploit seemingly trivial website vulnerabilities to easily steal customer payment information. “Magecart” is an umbrella term that applies to hacks in which outsiders inject specific, malicious JavaScript code onto e-commerce websites to collect shoppers’ payment information. It’s a subtle fraud technique that RiskIQ has detected on 2,086,529 sites, the security company said in a report published Friday. Notable victims have included British Airways and Ticketmaster, though the number of organizations affected continues to grow because hackers now are leveraging cloud servers and other hard-to-detect methods to steal data. The average Magecart infection lasts for 22 days, RiskIQ said. The company did not disclose which sites were included in the 2 million hit, saying only that the list included sites in Alexa’s ranking of the top 2,000 pages online. Meanwhile, […]
The post Magecart strikes more than 2 million websites as more groups get involved appeared first on CyberScoop.
Continue reading Magecart strikes more than 2 million websites as more groups get involved→