HomeSecurityVolusion: Hackers steal card details from customers of thousands of sites

Volusion: Hackers steal card details from customers of thousands of sites

VolusionSoftware company Volusion, which offers cloud services to online stores, has been the victim of a hacking attack. Hackers are distributing malicious code that records and steals payment card details that users into online forms during their purchases.

Volusion had previously reported having over 20,000 customers. It is estimated that the attack affected around 6,500 stores. However, the number could be higher.

One of Volusion's most important customers that was affected is online store Sesame Street Live.

The malicious code is still on servers and continues to affect the company's customers.

Already, many large companies are involved in investigating the attack (Check Point, Trend Micro, RiskIQ).

Hackers managed to gain access to Google Volusion's Cloud infrastructure. They then modified a JavaScript file and installed malicious code, aiming to record the card details that users enter when making purchases in online stores.

The file, modified by the hackers, is hosted at https://storage.googleapis.com/volusionapi/resources.js [copy] and is loaded into online stores supported by Volusion via the file /a/j/vnav.js.

Details about the malicious code can be found in the analysis published by Check Point researcher Marcel Afrahim.

Volusion: Hackers steal card details from customers of thousands of sites

According to the researchers, the attack is a classic example a Magecart or web card skimming attack. In this case, hackers steal details from online stores (rather than ATMs).

These attacks have become very common over the past two years. RiskIQ reported that Magecart attacks have occurred on more than 18,000 sites in the past few months.

Typically, hackers exploit vulnerabilities in self-hosted stores and install skimmers.

In this particular case, they breached a cloud-based platform (Volusion).

In May, hackers breached the cloud infrastructure of seven companies that provided services to online stores.

There have been other such attacks over the summer, affecting Amazon Web Services accounts. The current attack on Volusion is the first to be detected on Google Cloud.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS