Privacy News Attackers abscond with Newegg customers' credit-card info

Kuttz

Level 13
Thread author
Verified
Top Poster
Well-known
May 9, 2015
625
If you ordered anything from the site over the past few weeks, you'll probably want to contact your bank or credit-card provider and get a new set of account credentials.

In an unfortunate turn for the e-tailer, a group of hackers was able to insert malicious code into its checkout page and make off with customers' credit-card data, according to new reports from security firms RiskIQ and Volexity. According to those reports, the malicious code was active from August 16, 2018 to September 18, 2018.

The 'egg fell victim to a ring of data thieves known as Magecart. RiskIQ says that ring has attacked 800 or more e-commerce sites around the world, and notes that its code has preyed on customers of companies as large as British Airways and Ticketmaster. All it took to abscond with that information at Newegg was a mere eight lines of Javascript pointing back to a malicious domain, according to RiskIQ.

Newegg hasn't released a statement on the issue through its newsroom, but affected customers are apparently receiving emails from the company. Even if you haven't received one of those emails, we'd play it safe if you've ordered anything from the site of late and call your bank or financial services provider ASAP.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top