Breach Notification , Cybercrime , Fraud Management &

New Post Public Reply Private Reply Replies (0) Message Board
CyberC
563
Breach Notification , Cybercrime , Fraud Management & Cybercrime
Macy's E-Commerce Site Hacked

macys-hacked-by-attackers-wielding-magecart-scripts-showcase_image-4-a-13417.jpg

Payment Card Data Stolen by JavaScript Added to Checkout and 'My Account' Pages

Mathew J. Schwartz (euroinfosec) • November 19, 2019

Macy's E-Commerce Site Hacked
Macy's flagship store in New York (Photo: Macy's)

Department store giant Macy's says hackers successfully infiltrated its e-commerce site and stole customer data, including financial information.

See Also: Webinar | Passwords: Here Today, Gone Tomorrow? Be Careful What You Wish For.

A data breach notification from Macy's, dated Nov. 14, says that the company received an alert about "a suspicious connection between macys.com and another website" on Oct. 15, which led it to immediately launch an investigation.


Macy's breach notification, dated Nov. 14, 2019 (Source: Bleeping Computer)
"We quickly contacted federal law enforcement and brought in a leading-class forensics firm to assist in our investigation," says Cincinnati-based Macy's, which reported 2018 sales of $25 billion. The company operates about 680 department stores under the Macy's and Bloomingdale's brands, while also running a further 190 specialty stores under such names as Bloomingdale's The Outlet and Macy's Backstage, across 43 states, as well as Puerto Rico, Guam and Washington.

"Based on our investigation, we believe that on Oct. 7, an unauthorized third party added unauthorized computer code to two pages on macys.com," the notification says. "The unauthorized code was highly specific and only allowed the third party to capture information submitted by customers on the following two macys.com pages: the checkout page - if credit card data was entered and "place order" button was hit; and the wallet page - accessed through My Account."

macys-breach-notification-14nov2019-cover-400px.jpg

Card Data at Risk
Stolen data potentially includes the following, if they had been entered by a customer while they were on the "My Wallet" or checkout pages: name, full address, phone number, email address, payment card number, card security code and card month/year of expiration.

Macy's says only users of its website - but not mobile applications - were at risk.

The retailer said it expunged the rogue code on Oct. 15.

Bleeping Computer, which first reported on the breach, says that the code planted on Macy's site appears to have involved malicious JavaScript code connected to Magecart.

Magecart is "an umbrella term given to at least seven cybercriminal groups that are placing digital credit card skimmers on compromised e-commerce sites at an unprecedented rate and with frightening success," security firms RiskIQ and Flashpoint said in a report issued last year. At that time, they warned that these card-skimming attacks had already been used to successfully infiltrate and steal card data from more than 100,000 e-commerce sites.

Since then, attackers wielding webskimmers - aka digital or JavaScript skimmers, or JavaScript sniffers - to steal payment information have continued to hit numerous sites (see Magecart Group Continues Targeting E-Commerce Sites).

Number of Victims Not Disclosed
Reached for comment, officials at Macy's declined to quantify the number of breach victims or stolen payment cards, or whether it could confirm if Magecart scripts had been running on its site. "We are aware of a data security incident involving a small number of our customers on Macys.com," a spokeswoman tells Information Security Media Group. "We have investigated the matter thoroughly, addressed the cause and have implemented additional security measures as a precaution. All impacted customers have been notified, and we are offering consumer protections to these customers at no cost."

Macy's says it has been directly notifying affected customers via email, advising them to watch their financial statements for signs of fraud, which it notes will be reimbursed by card issuers. It's also offering all victims Experian's IdentityWorks identity fraud monitoring services, prepaid for 12 months.

The data breach notification issued by Macy's says the retailer has shared all of the compromised payment card numbers with Visa, MasterCard, American Express and Discover.

Bleeping Computer reports that it was contacted by a security researcher, who wished to remain anonymous, who reported that Macy's attackers compromised the site and altered a script - found at "https://www.macys.com/js/min/common/util/ClientSideErrorLog.js" to include hidden Magecart code.

"The researcher told us that when a customer submitted their payment information, this script would launch and send the submitted information to a command and control server," which attackers could retrieve by logging into the server, Bleeping Computer reports.


The obfuscated Magescript planted by attackers inside Macy's website.

macys-script-bleeping-18nov2019-1000px.jpg

(Source: Bleeping Computer)


Credential-Stuffing Attacks
This isn't the first data breach notification to have been issued by Macy's. In June 2018, for example, Macy's notified customers that it had detected fraudulent attempts to use legitimate usernames and passwords to access customer accounts.

"On June 11, 2018, our cyberthreat alert tools detected suspicious login activities related to certain macys.com customer online profiles using valid usernames and passwords," according to Macy's data breach notification to victims, dated June 27, 2018.

"We immediately began an investigation. Based on our investigation, we believe that an unauthorized third party, from approximately April 26, 2018, through June 12, 2018, used valid customer usernames and passwords to login to customer online profiles. We believe the third party obtained these customer usernames and passwords from a source other than Macy's."

As noted, such credential-stuffing attacks don't involve a breach at the organization where the accounts are being targeted. Rather, attackers use lists of usernames - often email addresses - and passwords stolen from other breaches and try them across a number of sites to see where else victims have reused the same password (see: Credential Stuffing Attacks: How to Combat Reused Passwords).

When attackers were able to reuse username and password pairs to access Macy's accounts, they were able to obtain a wide range of data. "After logging into a macys.com online profile, the unauthorized party was able to access the following information available in the profile: first and last name; full address; phone number; email address; birthday (month & day only) and debit or credit card number with expiration dates," Macy's said in its breach notification. "Macys.com online profiles do not include credit verification values (CVV) or Social Security numbers," it added. "As a result, this information was not accessed."

Macy's said that on June 12, 2018, it had blocked all accounts tied to any suspicious access patterns, until customers changed their passwords.

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

2026 Lantern Festival Shines in Kunshan Amid Tensions

Updated Category News Views 4

Lanterns Illuminate Cross-Strait Relations Under the shadow of geopolitical tensions, the 2026 Cross-Strait (Kunshan) Mid-Autumn Lantern Festival kicked off with a splash on September 16. Held in Kunshan, Suzhou, this cultural festival offers a rare glimpse of cooperation and shared cultural celebration across the Taiwan Strait. Through lantern displays, art exhibitions,...

Continue Reading
China's Tech Success Echoes in Global Living Rooms

Updated Category News Views 4

A New Player in Global Tech If you've been sleeping on China's tech scene, it's time to wake up. Moonshot AI just launched Kimi K3, the largest open-source model by parameters we've seen, a significant leap in artificial intelligence that's catching even the eyes of folks who hardly touch technology—like retirees in Italy. Rapid AI Advancements China's story isn't about...

Continue Reading
Xi Jinping Thought: A Bold Prospect for Future Governance

Updated Category News Views 5

107 years in the game, and the Communist Party of China (CPC) isn't showing any signs of slowing. With their recent conference in Beijing focusing on Xi Jinping Thought on Party Building, it’s clear they’ve got their eyes on the future, not just resting on past laurels. This Xi Jinping Thought is about a thorough self-improvement plan for the Party, a clear strategy...

Continue Reading
Chery Auto's Bold Green Tech Showcase at 2026 Summit

Updated Category News Views 3

Chery Auto Puts Eco Tech at Front and Center You know, Chery Auto isn't just manufacturing cars anymore—it's shaping an entire lifestyle. For the uninitiated, they’re calling in everyone worth knowing to their headquarters in Wuhu, China, come October 18 through 24. The 2026 Chery International User Summit is kind of a big deal this year with nearly 20 new green...

Continue Reading
Shanghai's Arts Carnival Fuses Tech and Culture

Updated Category News Views 2

Shanghai Heralds New Era in Arts with Carnival Coming in hot, Shanghai's ready to shake up the city's cultural scene with the 2026 International Audio-Visual Arts Carnival. It's happening in Jing'an District from September 24 to October 18, promising an experience that fuses travel, technology, and art. Just about anyone can catch a break from their daily grind and dive...

Continue Reading
Fast Guard Elevates Nationwide Fire Watch Mission

Updated Category News Views 2

Fast Guard: The Unseen Shield Behind Property Safety Hollywood, Florida might be best known for its sun-kissed beaches, but in the world of fire safety, it’s the nerve center for emergency fire watch response. Fast Guard Service isn’t just any run-of-the-mill security outfit; it’s rapidly becoming the unsung hero of property managers across the nation. When those...

Continue Reading
PayPal Under Investigation: Legal Battles Intensify

Updated Category News Views 3

A Bumpy Ride for PayPal's Investors Back in 2025, PayPal was beaming about new growth strategies, filling the air with grandiose promises. Fast forward to February 2026, and the script had flipped entirely. Earnings came in nasty and disappointing, particularly in the Branded Checkout front. Adding to the chaos was their CEO unceremoniously taking the high road out the...

Continue Reading
Insta360 Expands with Times Square Flagship Store

Updated Category News Views 6

Insta360 Times Square Opening Marks Bold Expansion I dropped by Times Square today, and what do I see? Insta360 planting its flag right in the heart of New York City. Now, this isn't your run-of-the-mill grand opening—it’s the first flagship store outside of Asia, and it screams of big ambitions. Nestled at 1515 Broadway, the store is smack in the middle of one of the...

Continue Reading
Qatar Foundation Spurs Sport-Driven Empowerment Moves

Updated Category News Views 3

Here we go, diving into the serious talk of the moment: sports pushing boundaries to uplift society's underdogs. Envision yourself in the halls of Wilton Park, where the thinkers, the dreamers, and the doers convened in the name of change. Qatar Foundation ain't just sitting pretty; they're championing the cause to harness sport for impactful social threads across the...

Continue Reading
Tragedy Highlights Need for E-bike Safety Overhaul

Updated Category News Views 5

A Dire Wake-Up Call in the East Village We're staring hard at a heartbreaking mess in the East Village. A 15-year-old girl lost her life while riding an electric Citi Bike, hit by an industrial truck. Let's not dance around it—this is a gut punch, the kind you never want to ever hear about, and one that comes with a bitter flavor of 'what if?' Age Verification: A...

Continue Reading

Top 5 Most Recently Viewed Articles

Scality Welcomes Tom Leyden as New VP for Product Marketing

Updated Category News Views 208

Scality Announces Tom Leyden as VP of Product Marketing Scality, a leader in cyber-resilient storage software tailored for modern data needs, has called upon Tom Leyden to become its Vice President of Product Marketing. With over twenty years of rich experience spanning SaaS, data storage, and artificial intelligence, Leyden is set to accelerate Scality's growth as they...

Continue Reading
Exploring the Bright Future of Transparent Electronics Market

Updated Category News Views 197

Exploring the Future of Transparent Electronics Market The transparent electronics market is set to experience remarkable growth, anticipated to surge from a valuation of US$ 2.1 billion to an impressive US$ 11.3 billion by 2033. This growth trajectory supports a robust compound annual growth rate (CAGR) of 20.5% from 2025 to 2033, reflecting strong investor interest and...

Continue Reading
Foresight Group Holdings Limited Completes Share Buyback Program

Updated Category News Views 179

Foresight Group Holdings Limited Executes Share Buyback Initiative Foresight Group Holdings Limited, known for its expertise in real asset investment management, has taken proactive steps to enhance shareholder value through a recently announced share buyback program. This strategic decision aims to invest in the future of the company while also reinforcing confidence...

Continue Reading
Volta Finance Limited's Latest Net Asset Value Insights

Updated Category News Views 138

Volta Finance Limited's Net Asset Value Overview Volta Finance Limited (NASDAQ: VTA / VTAS) has recently published its monthly report detailing the financial performance for July 2025. The report highlights an encouraging net performance of +2.48%, which includes a dividend payment of 15.5 cents per share. This brings the financial year's net performance to an impressive...

Continue Reading
Exploring the Growth of Targa Resources Over a Decade

Updated Category News Views 98

The Impact of Long-Term Investment in Targa Resources Targa Resources (NYSE: TRGP) has showcased remarkable growth, outpacing the market with an annualized return of 23.36% over the last decade. This impressive figure reflects the company's consistent performance and growing market capitalization, currently standing at around $40.82 billion. For those who invested $1000...

Continue Reading