Experts Comments On Macy’s Customer Payment Info Stolen In Magecart Breach

Macy’s has disclosed a data breach  – their web site was hacked with malicious scripts that steal customer’s payment information. In Magecart attacks,  hackers compromise web sites to inject malicious JavaScript scripts into various sections of the web site. These scripts then steal payment information that is submitted by a customer.

The ‘Notice of Data Breach‘ issued by Macy’s said their web site was hacked on October 7th, 2019 and a malicious script was added to the ‘Checkout’ and ‘My Wallet’ pages. If any payment information was submitted on these pages while they were compromised, the credit card details and customer information was sent to a remote site under the attacker’s control.

Chris Kennedy, CISO and VP of Customer Success ,  AttackIQ
November 22, 2019
Companies should proactively test and evaluate their cybersecurity posture to find vulnerabilities and remediate them.
Consumers trust companies to keep their data secure and with the holiday season around the corner, this is at the top of mind. Cybercriminals are continuously looking for gaps in security defenses and vulnerabilities to turn a quick profit. In this incident, valuable financial information was stolen including credit card numbers, security codes and expiration dates. During peak holiday shopping se ....
[Read More >>]
Kevin Lancaster, General Manager of Security Solutions,  Kaseya
November 22, 2019
Compliance with these standards helps retailers protect payment card data by restricting physical and digital business access.
First and foremost, retailers must ensure they are complying with the Payment Card Industry Data Security Standard (PCI DSS). Compliance with these standards helps retailers protect payment card data by restricting physical and digital business access to cardholder data and requiring multi-factor authentication for all non-console administrative access. None of these processes alone will ensure co ....
[Read More >>]
Lev Lesokhin, SVP of Strategy and Analytics,  CAST
November 21, 2019
Putting a stop to code injection is one of the oldest tenets in the app sec playbook.
While we commend Macy’s for finding the breach and dealing with it only about a week after it first occurred, with the right precautions this is easily avoidable. Putting a stop to code injection is one of the oldest tenets in the app sec playbook. That said, with modern applications, consisting of multiple layers, components and interstitial APIs, that task is becoming increasingly difficul ....
[Read More >>]
Elad Shapira, Head of Research,  Panorays
November 20, 2019
Online retailers like Macy’s are prime targets for Magecart.
The recent data breach at Macy's is unfortunate, but not surprising. Magecart is responsible for cyberattacks on many major companies including Ticketmaster, British Airways, NewEgg, Magento and more. Online retailers like Macy’s are prime targets for Magecart, because data is easily stolen during checkout, often through third parties, as customers enter their credit cards. For this reason, orga ....
[Read More >>]
Mike Bittner, Associate Director of Digital Security and Operations,  The Media Trust
November 20, 2019
Treat everyone else as a potential threat.
The challenge with preventing cross-site scripting attacks is identifying which code should be running on a site, which ones shouldn't. Until site owners know all the domains that are called by code on their site, they won't be able to distinguish who's authorized to be there, and who isn't. If they have an inventory of allowed digital vendors, they'll be able to root out unauthorized actors like ....
[Read More >>]
Robert Prigge, CEO,  Jumio
November 20, 2019
Javelin’s 2019 Identity Fraud Study reported $4 billion in ATO losses last year and new account fraud losses of $3.4 billion.
The Macy’s data breach is concerning for two reasons. First, it released even more personally identifiable information into the dark web including names, emails, addresses and credit card information. This compromised data can be combined with other available information to create a “fullz,” giving criminals everything they need to commit identity theft. 2019 has been a record year for fraud ....
[Read More >>]
Peter Draper, Technical Director, EMEA,  Gurucul
November 19, 2019
Identifying anomalous traffic quickly and taking action can reduce the impact of such attacks.
Mergecart attacks in action again. A number of organisations have been compromised in this way, including the 2019 British Airways breach. Managing and controlling what can and cannot be run on your website is critical in ensuring the security of your customers' data. Likewise having the capability to monitor behaviour and traffic to and from your estate is becoming a must. Identifying anomalous t ....
[Read More >>]

If you are an expert on this topic:

Submit Your Expert Comments

In this article