1 min read

Ticketmaster falls victim to worldwide digital card skimming attack

Luana PASCU

July 16, 2018

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
Ticketmaster falls victim to worldwide digital card skimming attack

At the end of June, online ticket company Ticketmaster confirmed that Inbenta, a third-party website supplier, suffered a security incident. However, researchers now reveal it was more complicated than it appeared, and definitely not a one-time attack, reported RiskIQ.

Investigations show it was part of a highly sophisticated scam that targeted 800 e-commerce sites worldwide. The hackers responsible go by the name Magecart, a group of digital card skimmers with an elaborate technique: attacking companies that integrate their software with Ticketmaster and replace their javascript modules with malicious code designed to steal payment information. For example, Inbenta”s javascript module was compromised in this scam campaign. Besides its UK site, a number of Ticketmaster websites were affected, including sites from Ireland, Turkey and New Zealand.

“Ticketmaster Germany, Ticketmaster Australia and Ticketmaster International (previously mentioned in the Inbenta breach) were also compromised via another completely different third-party supplier of functionality,” the firm said.

It seems website hacking has lost its glory and Magecart is a group that researchers are familiar with, having expressed concern about them in the past. The breach affected other providers including a social media integration company, a web analytics company and a CMS platform. According to research, the hackers have been sending the skimmed payment details to a server from as early as December 2016

“Our investigation following the Inbenta breach uncovered evidence that the Inbenta attack was not a one-off, but instead indicative of a change in strategy by Magecart from focusing on piecemeal compromises to targeting third-party providers like Inbenta to perform more widespread compromises of card data,” analysts wrote.

tags


Author



Right now

Top posts

The Holiday Guide to Tech Support: Fixing the Family Computer

The Holiday Guide to Tech Support: Fixing the Family Computer

November 24, 2021

2 min read
Bitdefender Celebrates 20 Years of Cybersecurity Leadership

Bitdefender Celebrates 20 Years of Cybersecurity Leadership

November 04, 2021

3 min read
Bitdefender Study Reveals How Consumers Like (and Dislike) Managing Passwords

Bitdefender Study Reveals How Consumers Like (and Dislike) Managing Passwords

October 26, 2021

3 min read
What are drive-by download attacks and how do you prevent them?

What are drive-by download attacks and how do you prevent them?

October 25, 2021

2 min read
Criminals Can't Wait to Add Your IoT Device to Their DDoS Networks

Criminals Can't Wait to Add Your IoT Device to Their DDoS Networks

October 22, 2021

2 min read
Six in 10 Consumers Faced a Cyber Threat in 2021, New Bitdefender Study Reveals

Six in 10 Consumers Faced a Cyber Threat in 2021, New Bitdefender Study Reveals

October 20, 2021

3 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Phishers Targeting Victims with ‘Free’ PCR Test for Omicron COVID-19 Variant Phishers Targeting Victims with ‘Free’ PCR Test for Omicron COVID-19 Variant
Filip TRUȚĂ

December 03, 2021

2 min read
WordPress Plugin Vulnerability Affected More than 80,000 Websites; Patch Is Now Out WordPress Plugin Vulnerability Affected More than 80,000 Websites; Patch Is Now Out
Silviu STAHIE

December 03, 2021

1 min read
Man charged with Ubiquiti data breach and extortion was employee assigned to investigate hack Man charged with Ubiquiti data breach and extortion was employee assigned to investigate hack
Graham CLULEY

December 03, 2021

2 min read