0 Replies Latest reply on Sep 19, 2018 6:55 PM by black_zion

    Newegg hacked for over a month, from August 14 and September 18, payment details compromised

    black_zion

      How is it Chinese owned Newegg failed to notice such a major security breach for over a month...Another good example of why you should never use your debit card for any purchase.

       

      https://www.tomshardware.com/news/newegg-cyber-security-breach,37818.html

      "The breach of Newegg shows the true extent of Magecart operators’ reach. These attacks are not confined to certain geolocations or specific industries—any organization that processes payments online is a target. The elements of the British Airways attacks were all present in the attack on Newegg: they integrated with the victim’s payment system and blended with the infrastructure, staying there as long as possible."

       

      The attack itself used malicious JavaScript on the "secure.newegg.com" domain to steal financial information during the checkout process. Volexity said in a blog post today that the script waits for a page to load, allows the victim to fill out their payment info and then allows the data "to be submitted to the attacker-specified destination when a mouse button is released" or "when a touch screen has been pressed and released."

       

      That compromised information was sent to a domain the attackers set up at "neweggstats.com" via SSL/TLS. Magecart registered the domain on August 13, and not long after, compromised Newegg's website to place the skimmer code. The researchers said the malicious JavaScript was gone from Newegg's checkout page on September 18, so the attackers were likely able to steal data from a full month's worth of transactions.

       

      Newegg has yet to disclose the attack on its site, but the company did tweet about the attack shortly after it was made public: "Yesterday we learned one of our servers had been injected with malware which was identified and removed from our site. We’re conducting extensive research to determine exactly what info was obtained and are sending emails to customers potentially impacted. Please check your email."

       

      We've reached out to Newegg for a statement about the attack and how it plans to respond. More information about how many people were affected by the attack should be discovered after Newegg looks back at its transaction history and determines whether or not everyone who bought something between August 14 and September 18 was at risk. In the meantime, keep a close eye on your bank accounts, enthusiasts.