HomeSecurityWarner Music Group: Hack in its online stores. Customer data stolen!

Warner Music Group: Hack in its online stores. Customer data stolen!

Warner Music Group (WMG), the world's third-largest record label, has disclosed a hack affecting the personal and financial data of its customers after many of its US- fell victim Magecart attack last April.


With over 200 years in the music business, Warner Music Group employs more than 3,500 people and operates in more than 70 countries. WMG also operates Warner Chappell Music and some of the world's most successful record labels, including Elektra, Warner Records, Atlantic, Warner Classics, Parlophone and Warner Music Nashville.

Warner Music Group

The company said the hack affected a large number of e-commerce sites operated by a third-party service provider. It also said the breach may have allowed hackers to steal personal customer data entered on the sites. The company also notified customers affected by the breach in a letter saying that on August 5, 2020, it discovered that U.S.-based e-commerce sites operated by the company but hosted and supported by a third-party service provider had been compromised. This allowed hackers to obtain a copy of personal information that the company’s customers had entered on one or more of the affected sites between April 25, 2020, and August 5, 2020.

In addition, Warner Music Group noted that although it conducted an investigation that found no evidence that the information was leaked, it does not rule out the possibility that something like this could happen in the future and warns its customers of the risk that hackers could carry out malicious and "fraudulent" activity using the personal and financial data that was possibly stolen during the attack.

Warner Music Group hack

Warner Music Group also added that all information entered by affected customers into the online stores that appear to have been compromised may have been collected and stolen by the attackers after products were placed in shopping carts.

The stolen information may have included customer names, email, phone numbers, billing addresses, shipping addresses and credit card information. However, according to WMG's letter, information entered when making PayPal on the affected e-commerce sites was not affected.

Warner Music Group-hack-online stores-customer data

Warner Music Group also emphasized that as soon as it discovered the hack, it launched a thorough investigation with the help of leading security experts, while taking immediate action to address and correct the problem. It also informed credit card providers and law enforcement authorities, with whom it continues to cooperate in its investigation.

Warner Music Group is offering 12 months of free identity monitoring services through Kroll to those affected and recommends that they remain vigilant for any unauthorized use of their credit cards or suspicious email communications, especially those claiming to come from Warner Music Group or any site associated with the company.

Kroll

Although Warner Music Group did not provide any information on how the attackers were able to compromise the stores and potentially obtain personal and financial data from customers, it appears to be a Magecart attack. This is a type of attack in which hacking gangs, known as Magecart groups, infiltrate e-commerce store sites and inject malicious JavaScript-based scripts into the source of checkout pages as part of web skimming (or e-skimming) attacks. Their goal is to collect all payment and personal information submitted by customers of the compromised online stores and transfer it to remote servers under their control.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS