More than 4,000 online retailers have been notified that their websites had been compromised by cybercriminals who were trying to steal payment information and other personal information from customers.
See also: Hackers deploy Linux malware on e-commerce servers

The National Cyber Security Centre (NCSC) has identified a total of 4,151 retailers that were breached by hackers attempting to exploit vulnerabilities in checkout pages to divert payments and steal details. Retailers were notified of the breaches over the past 18 months.
The majority of online stores that hackers exploited for payment-skimming attacks had known vulnerabilities in the Magento e-commerce platform. Most of those affected and notified of the breaches and vulnerabilities are small and medium-sized businesses.
See also: E-commerce: Fraud losses expected to exceed $20 billion in 2021
The NCSC has revealed the number of businesses it has notified of customer data theft ahead of Black Friday. It is urging all retailers to ensure their websites are secure ahead of the busiest online shopping period of the year to protect their business – and their customers – from cybercriminals.
One of the key things online retailers can do to prevent payment and personal data is to apply available security patches that prevent cybercriminals from exploiting known vulnerabilities in Magento and any other software they use.

See also: How to protect e-commerce sites from client-side attacks?
Timely patching is just one of the things recommended in the NCSC and British Retail Consortium’s Cyber Resilience Toolkit For Retail. This kit was released in October 2020, but the information on protecting websites from cyberattacks is still very important.
The compromised shopping websites were identified as part of the NCSC's Active Cyber Defense program, which has been monitoring for vulnerabilities that could affect online retailers since April 2020.
The NCSC has also published advice for consumers on how to stay safe when shopping online. The advice includes being selective about where you shop, only providing necessary information, ensuring the payment system used is protected and keeping your online accounts secure.
Information source: zdnet.com
