HomeSecurityFBI warns businesses about e-skimming attacks

FBI warns businesses about e-skimming attacks

The FBI is warning U.S. private sector businesses about the rise of e-skimming attacks, often called Magecart attacks .e-skimming

E-skimming attacks involve the hacking of e-commerce sites and the introduction of malicious code, which is used to collect payment card information from the sites' customers.

According to the FBI, small and medium-sized businesses, as well as government agencies, that allow online credit card payments are at greatest risk.

Criminals insert malicious code into a site after first gaining access to it through a phishing attack or some other method.

E-skimming attacks first appeared in 2016. Since then, a significant increase in their number has been observed.

The criminals behind these attacks use a variety of techniques. They exploit vulnerabilities in e-commerce platforms, hack plugins used by the platforms, install skimmers, and more.

FBI warns businesses about e-skimming attacks

Criminals can also target platform administrators through social engineering and obtain credentials . With the credentials, they gain access to the online store and install the malicious code.

The most common technique is the installation of software skimmers, which help hackers steal the card details of the sites.

Security companies have been monitoring the activity of groups that carry out e-skimming attacks for years .

RiskIQ FlashPoint published a report that shows that some groups are using more sophisticated techniques than others. The group called Group 4 is one of the most dangerous.

The victims of these attacks are many and among them are large companiessuch as British Airways, Newegg, Ticketmaster, MyPillow, Amerisleep and Feedify.

Security experts estimate that Magecart attacks have affected millions of users.

The FBI advises all companies, especially small and medium-sized businesses, as well as government agencies, to take some time to prevent e-skimming attacks.

's advice is as follows:

  1. Regularly update all your systems and fix any security issues that arise. Always use the latest software . Anti-virus and anti-malware software should always be up to date. Finally, use strong firewalls.
  2. Change the login credentials on all systems. Do not use the default ones.
  3. Train employees to identify suspicious activity. Organize seminars to learn safe cyber practices.
  4. Separate your network. Don't allow anyone to connect to the network.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS