Magecart Hackers Have Hacked Newegg, the Giant of Online Hardware Sales

in #writing6 years ago

For more than a month, this group of hackers have siphoned the bank cards numbers on Newegg, an e-commerce site which receives more than 50 million visitors a month.

Specialized in the theft of credit card data, Magecart’s hackers keep their momentum. After Ticketmaster last June, British Airways and Feedify last week, it's the turn of Newegg, American specialist in the online sale of computer equipment to fall in the nets of these cyber-criminals.

hack-3671982_1280.jpg

The modus operandi is similar to the one which affected the British company. The Magecart group managed to hack the Newegg’s servers and to place a malicious code directly on the payment page.

At the moment the buyer confirms his banking data, these are automatically transferred towards a controlled server by the hackers: card number, validity date and three-digit security code.

According to RiskIQ’s analysis, IT security specialist, this hostile code was injected around August 14th. The hackers were thus able to siphon banking data during more than a month. It’s not nothing because Newegg is not a small player. This company generated $ 2,65 billion in 2016 and receives more than 50 million visitors a month.

RiskIQ therefore considers that the number of victims is "massive". Probably on the order of several millions, even tens millions…

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

Several ways to protect yourself

This attack proves that e-commerce sites are not enough secured. As user, there are several ways to protect yourself, starting with the activation of the 3D Secure protection.
In this case, the transactions must be validated by one single-use code sent by SMS. Unfortunately, not all e-commerce sites integrate this system.

Other solution: use a virtual bank card. This system allows to generate single-use card number for each online purchase.

" It is an effective method to counter the fraud after attacks. That’s our main recommendation ", explains Yonathan Klijnsman, security researcher at RiskIQ.

Finally, if you make purchases on a site that has registered your bank card in its databases, you have nothing to be afraid of because the card numbers are no longer filled in forms.
It’s the case if you make 1-Click shopping on Amazon or on Apple iTunes for example.

If you have questions and if you need advice, just let me know!

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Sort:  

@vijbzabyss really an amazing and interesting post this is truelly appreciatable because through this post most of the peoplle who dont know anything about hacking and these types of cyber attacks on the internet which are taking place day by day in a really high in number this post helps and make them aware and will be able to keep theselves safe through these attacks lovevly work sir keep going

smart hackers.

Posted using Partiko Android

Coin Marketplace

STEEM 0.20
TRX 0.19
JST 0.034
BTC 91382.97
ETH 3119.60
USDT 1.00
SBD 2.91