iOttie , a company that makes car parts and accessories, announced that its website was hacked for nearly two months, leading to a data breach. information and credit cards Online shoppers' personal were likely stolen

iOttie has issued a statement regarding the data breach. The company discovered on June 13 that its online store was compromised between April 12, 2023, and June 2 with malicious scripts.
The company is talking about a possible e-skimming attack, but informs customers that on June 2, 2023, during a WordPress/plugin update, the malicious code was removed.
“However, (the attackers) could have obtained your credit card details,” iOttie warns.
See also: Russian hackers APT28 breached email servers of Ukrainian organizations
iOttie did not mention the number of customers affected, but noted that the attackers could have gained access to information such as names, personal information and payment information (e.g. bank account, credit and debit cards, security codes, passwords and PINs).
This type of attack is known as MageCart. Attackers hack online stores to inject malicious JavaScript into checkout pages. When the shopper submits their credit card details and other personal information, the malicious script steals the data and sends it to the attackers.
Then, with this data in their hands, attackers can commit financial fraud, identity theft, or sell the data to other threat actors on dark web marketplaces.
See also: Oregon and Louisiana: Millions of identities stolen in MOVEit breach

Due to the detailed information that may have been exposed in this attack, all iOttie customers who purchased a product between April 12 and June 2 should check their bank accounts and credit cards for possible suspicious activity.
iOttie did not provide details on how its site was compromised, but its online store is a WordPress with the WooCommerce merchant plugin.
Cybercriminals often target WordPress sites, using vulnerabilities found in plugins.
Since iOttie said the malicious code was removed with a plugin update, we can assume with relative certainty that the hackers likely compromised the site by exploiting a vulnerability in one of the WordPress plugins.
See also: Have I Been Pwned warns of new Zacks data breach
Exploiting these vulnerabilities can lead to more sophisticated attacks or data breaches, as was the case with iOttie. Data breaches can have devastating consequences, but there are steps you can take to mitigate the risks. Regularly updating your software, using strong passwords , and restricting personal information are good practices to adopt.
Source: www.bleepingcomputer.com
