Breach Notification , Cybercrime , Fraud Management &

New Post Public Reply Private Reply Replies (0) Message Board
CyberC
566
Breach Notification , Cybercrime , Fraud Management & Cybercrime
Macy's E-Commerce Site Hacked

macys-hacked-by-attackers-wielding-magecart-scripts-showcase_image-4-a-13417.jpg

Payment Card Data Stolen by JavaScript Added to Checkout and 'My Account' Pages

Mathew J. Schwartz (euroinfosec) • November 19, 2019

Macy's E-Commerce Site Hacked
Macy's flagship store in New York (Photo: Macy's)

Department store giant Macy's says hackers successfully infiltrated its e-commerce site and stole customer data, including financial information.

See Also: Webinar | Passwords: Here Today, Gone Tomorrow? Be Careful What You Wish For.

A data breach notification from Macy's, dated Nov. 14, says that the company received an alert about "a suspicious connection between macys.com and another website" on Oct. 15, which led it to immediately launch an investigation.


Macy's breach notification, dated Nov. 14, 2019 (Source: Bleeping Computer)
"We quickly contacted federal law enforcement and brought in a leading-class forensics firm to assist in our investigation," says Cincinnati-based Macy's, which reported 2018 sales of $25 billion. The company operates about 680 department stores under the Macy's and Bloomingdale's brands, while also running a further 190 specialty stores under such names as Bloomingdale's The Outlet and Macy's Backstage, across 43 states, as well as Puerto Rico, Guam and Washington.

"Based on our investigation, we believe that on Oct. 7, an unauthorized third party added unauthorized computer code to two pages on macys.com," the notification says. "The unauthorized code was highly specific and only allowed the third party to capture information submitted by customers on the following two macys.com pages: the checkout page - if credit card data was entered and "place order" button was hit; and the wallet page - accessed through My Account."

macys-breach-notification-14nov2019-cover-400px.jpg

Card Data at Risk
Stolen data potentially includes the following, if they had been entered by a customer while they were on the "My Wallet" or checkout pages: name, full address, phone number, email address, payment card number, card security code and card month/year of expiration.

Macy's says only users of its website - but not mobile applications - were at risk.

The retailer said it expunged the rogue code on Oct. 15.

Bleeping Computer, which first reported on the breach, says that the code planted on Macy's site appears to have involved malicious JavaScript code connected to Magecart.

Magecart is "an umbrella term given to at least seven cybercriminal groups that are placing digital credit card skimmers on compromised e-commerce sites at an unprecedented rate and with frightening success," security firms RiskIQ and Flashpoint said in a report issued last year. At that time, they warned that these card-skimming attacks had already been used to successfully infiltrate and steal card data from more than 100,000 e-commerce sites.

Since then, attackers wielding webskimmers - aka digital or JavaScript skimmers, or JavaScript sniffers - to steal payment information have continued to hit numerous sites (see Magecart Group Continues Targeting E-Commerce Sites).

Number of Victims Not Disclosed
Reached for comment, officials at Macy's declined to quantify the number of breach victims or stolen payment cards, or whether it could confirm if Magecart scripts had been running on its site. "We are aware of a data security incident involving a small number of our customers on Macys.com," a spokeswoman tells Information Security Media Group. "We have investigated the matter thoroughly, addressed the cause and have implemented additional security measures as a precaution. All impacted customers have been notified, and we are offering consumer protections to these customers at no cost."

Macy's says it has been directly notifying affected customers via email, advising them to watch their financial statements for signs of fraud, which it notes will be reimbursed by card issuers. It's also offering all victims Experian's IdentityWorks identity fraud monitoring services, prepaid for 12 months.

The data breach notification issued by Macy's says the retailer has shared all of the compromised payment card numbers with Visa, MasterCard, American Express and Discover.

Bleeping Computer reports that it was contacted by a security researcher, who wished to remain anonymous, who reported that Macy's attackers compromised the site and altered a script - found at "https://www.macys.com/js/min/common/util/ClientSideErrorLog.js" to include hidden Magecart code.

"The researcher told us that when a customer submitted their payment information, this script would launch and send the submitted information to a command and control server," which attackers could retrieve by logging into the server, Bleeping Computer reports.


The obfuscated Magescript planted by attackers inside Macy's website.

macys-script-bleeping-18nov2019-1000px.jpg

(Source: Bleeping Computer)


Credential-Stuffing Attacks
This isn't the first data breach notification to have been issued by Macy's. In June 2018, for example, Macy's notified customers that it had detected fraudulent attempts to use legitimate usernames and passwords to access customer accounts.

"On June 11, 2018, our cyberthreat alert tools detected suspicious login activities related to certain macys.com customer online profiles using valid usernames and passwords," according to Macy's data breach notification to victims, dated June 27, 2018.

"We immediately began an investigation. Based on our investigation, we believe that an unauthorized third party, from approximately April 26, 2018, through June 12, 2018, used valid customer usernames and passwords to login to customer online profiles. We believe the third party obtained these customer usernames and passwords from a source other than Macy's."

As noted, such credential-stuffing attacks don't involve a breach at the organization where the accounts are being targeted. Rather, attackers use lists of usernames - often email addresses - and passwords stolen from other breaches and try them across a number of sites to see where else victims have reused the same password (see: Credential Stuffing Attacks: How to Combat Reused Passwords).

When attackers were able to reuse username and password pairs to access Macy's accounts, they were able to obtain a wide range of data. "After logging into a macys.com online profile, the unauthorized party was able to access the following information available in the profile: first and last name; full address; phone number; email address; birthday (month & day only) and debit or credit card number with expiration dates," Macy's said in its breach notification. "Macys.com online profiles do not include credit verification values (CVV) or Social Security numbers," it added. "As a result, this information was not accessed."

Macy's said that on June 12, 2018, it had blocked all accounts tied to any suspicious access patterns, until customers changed their passwords.

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

Epic Political Thriller Explores Humanity's Future

Updated Category News Views 11

Adams' Provocative Debut Asks Timeless Questions Sometimes life throws a philosophical curveball, and that's exactly what John C. Adams has done with his debut novel, The Third Phase. This isn't your average political yarn—it's an intricate tapestry intertwining political intrigue, deep spiritual inquiry, and hearty doses of classic philosophy. A Whirlwind Journey...

Continue Reading
NYSE Texas Redefines the U.S. Capital Markets Landscape

Updated Category News Views 17

NYSE Texas: Carving a Niche The notion of 'Y'all Street' might seem like a gimmick, but NYSE Texas is pushing a serious agenda with its newly released white paper, 'NYSE Texas and the Reshaping of U.S. Capital Markets.' This is no small feat. Texas is already housing 235 NYSE-listed companies, boasting a colossal combined worth of $4.8 trillion. With 130 of these firms...

Continue Reading
TA Services Strengthens U.S.-Mexico Freight Operations

Updated Category News Views 19

TA Services Moves Boldly Across Borders If ever there was a time to play the logistics chessboard like a champ, it's now, and TA Services just slammed the board with a solid move. They've grabbed Carmen Pacheco Transportation and Interload Forwarding, two family-run operations with some real muscle in North American logistics. This isn't a small-time maneuver; they've...

Continue Reading
Dentistry.One Achieves HITRUST i1, Boosts Cybertrust

Updated Category News Views 12

HITRUST i1 Certification: The Gold Standard in Security For a world increasingly reliant on digital infrastructure, cybersecurity certification is no longer just a badge of honor; it's a cornerstone of trust. Dentistry.One nailed this down by bagging that coveted HITRUST i1 certification. When folks talk about securing data, HITRUST might as well be speaking gospel. We're...

Continue Reading
Truss Financial Tackles Home Equity Closing Delays

Updated Category News Views 23

Truss Financial Group's Bold Move Against Closing Delays In real estate, time is money. Even the most casual market observer could tell you delays can slice through a deal like a hot knife through butter. That's the headache home equity borrowers face, blindsided by closing delays that sneak up on them without warning. An Industry Bottleneck Finally Addressed Enter Truss...

Continue Reading
Skandia's Soundproofing Kit Expands to Brazil's Skies

Updated Category News Views 13

Soundproofing Takes Off in Brazil Skandia has just pulled off a neat trick, earning the nod from Brazil's National Civil Aviation Agency (ANAC) for their King Air soundproofing kit. That means quieter skies ahead for operators of the King Air 200 and 300 series in Brazil. This is no small feat, folks; it's like finally getting that coveted backstage pass after years of...

Continue Reading
IWP and VYRE Unveil 'The Plug' for VBNGtv Content

Updated Category News Views 18

Bringing Capital and Content Under One Roof There's something in the air as Itibari-Waynne & Partners (IWP) team up with the VYRE Network to crank out a fresh slate of content for VYRE Business News Global (VBNGtv). This partnership ain't just another splash in the buzzy world of digital media; it's like merging Wall Street with Hollywood. IWP, prepping to go full...

Continue Reading
Karoo Health Leaps Forward with New CCO Breton

Updated Category News Views 15

Change of Guard in Cardiac Health at Karoo Here's a move that might shake things up in the healthtech sector: Karoo Health just snagged Angela "Angie" Breton as their new Chief Commercial Officer. It's like putting a seasoned captain at the helm right before setting sail on uncharted waters. Breton's not just any captain—she's got a hefty 25 years of experience...

Continue Reading
Bob Evans' Protein Mac & Cheese: Practical Power Play

Updated Category News Views 21

Has anyone else noticed just how fast the world spins when it comes to consumer trends these days? Bob Evans is hopping right on the protein bandwagon with its latest launch, a microwave-ready Protein Macaroni & Cheese that packs 18 grams of protein per serving. You gotta hand it to them for seizing opportunity when they see it. This one's not just about tossing a new...

Continue Reading
Purina Institute Highlights Nutritional Science at WSAVA 2026

Updated Category News Views 19

A Global Stage for Pet Nutrition Science The folks over at the Purina Institute are back in the spotlight as they gear up to throw their weight behind the 51st World Small Animal Veterinary Association (WSAVA) Congress in Warsaw, Poland. Set for October 13-15, 2026, this isn’t just another event—they're bringing some serious clout with their 'Food for Thought'...

Continue Reading

Top 5 Most Recently Viewed Articles

Investors Urged to Act Before Deadline in Charter Class Action

Updated Category News Views 95

Investors Take Note of Charter Communications Lawsuit In an important development, investors in Charter Communications, Inc. (NASDAQ: CHTR) are being advised of a notable class action lawsuit. This situation demands the attention of those who have invested and could potentially have implications for numerous shareholders. Understanding the Lawsuit The lawsuit against...

Continue Reading
L.B. Foster Company Earnings Report and Conference Call Details

Updated Category News Views 94

L.B. Foster Company Earnings Report Announcement PITTSBURGH — L.B. Foster Company (NASDAQ: FSTR) has made an important announcement regarding its upcoming fourth quarter and full year 2024 operating results. The results will be released pre-market on Tuesday, March 4, 2025. This is a significant period for the company as stakeholders eagerly anticipate performance...

Continue Reading
Rising Talents Shine at Shanghai Film Festival 2026

Updated Category News Views 21

A Dazzling Conclusion to SIFF's 28th Edition The golden aura of film magic was in full swing at this year's Shanghai International Film Festival, reaching a crescendo on June 20 at the renowned Shanghai Grand Theatre. Delight swept through the audience as the Golden Goblet Awards unfolded before a crowd of filmmakers and industry heavyweights from across the globe. This...

Continue Reading
Medallion Financial Corp. Achieves Growth with Strong Q2 Results

Updated Category News Views 96

Medallion Financial Corp. Shows Remarkable Performance in Q2 2025 In an impressive display of growth, Medallion Financial Corp. (MFIN) has announced its financial results for the second quarter, marking a substantial rise in net income compared to the same period last year. The specialty finance company, known for originating and servicing loans across various consumer...

Continue Reading
JPMorgan's Updated Forecast Enhances Take-Two's Stock Prospects

Updated Category News Views 57

JPMorgan's Strategic View on Take-Two's Future Recently, JPMorgan adjusted its outlook for Take-Two Interactive (NASDAQ:TTWO), modifying the price target from $200 to $195 while maintaining an Overweight rating on the stock. This adjustment comes on the heels of a reassessment of the company’s second-quarter and fiscal year 2025 projections, which were set at the lower...

Continue Reading