
More than 24 SQL databases online stores have been stolen and put up for sale on a public site. In total, the seller is providing over 1.5 million rows of records, but the stolen data is much more.
The attacker breaches unsecured servers, copies databases, and leaves a note demanding ransom from online store operators.
The hacker gives victims 10 days to pay 0.06 BTC ($525) within that time. If they don't, the hacker threatens to publish the database online.
Some of the attacker's wallets showed that he had taken money from at least 100 victims. The amount found in his possession was 5.8 BTC (about $51,000).
Based on transaction dates and reports from multiple online stores, the attacker is very active. This month alone, there have been nine reports of attacks and extortion.

Attacker targets e-commerce platforms
The attacker has published 31 databases on the website, although the number of attacks is much higher (judging by the number of reports). The most recent database is from March, and all have a sample attached so potential buyers can get an idea.
More than half of the databases listed belong to online stores in Germany. The rest are from stores in Brazil, the USA, Italy, India, Spain and Belarus. In all cases e-commerce platforms, such as: Shopware, JTL-Shop, PrestaShop, OpenCart, Magento v1 and v2.
Depending on the store, the data contains email, names, hashed passwords (e.g. bcrypt, MD5), postal addresses, gender, dates of birth.
The theft of online store databases and the type of attack are reminiscent of the MongoDB ransomware attacks that peaked in 2017 and continued into 2019.
Databases are still attractive to cybercriminals . Although the profits are not as large as other types of extortion, crooks can increase them by selling them to others.
