HomeSecurityHackers steal ZAGG customers' credit cards in breach

Hackers steal credit cards from ZAGG customers in breach

ZAGG is informing customers that their credit card data has been exposed to unauthorized individuals following a breach of a third-party applicationprovided by the company's e-commerce provider BigCommerce.

See also: BeyondTrust: Hackers breached Remote Support SaaS tools

ZAGG violation

ZAGG is a consumer electronics manufacturer known for its mobile accessories, such as screen protectors, phone cases, keyboards and power banks. The Utah-based company has annual revenue of $600 million.

According to the letter sent to affected individuals, the attacker compromised the FreshClicks provided by BigCommerce and introduced malicious code that stole shoppers' card details.

BigCommerce is an software-as-a-service (SaaS) e-commerce platform provider that serves a wide range of businesses, from small to large corporations, across a variety of industries and regions.

FreshClick, which was a victim of the breach affecting ZAGG, is a third-party application that helps build apps and responsive websites for the BigCommerce platform. It is designed to improve the functionality of online stores and improve the customer experience.

Although FreshClick is not developed directly by BigCommerce, it is offered through the platform's app market, which is a curated space for merchants to find and install add-ons for their stores.

See also: 390,000 WordPress accounts stolen by hackers

In a statement, BigCommerce stressed that its systems were not compromised. Using internal tools, the company discovered that the FreshClicks app had been compromised and uninstalled it from its customers' stores.

Hackers steal credit cards from ZAGG customers in breach

As a result of this data breach, the attacker stole names, addresses, and payment card data belonging to shoppers on zagg.com between October 26 and November 7, 2024.

In response to this incident, ZAGG implemented remediation measures, notified federal law enforcement and regulators , and arranged for affected individuals to receive a free 12-month credit monitoring service through Experian.

Recipients of the letters are also advised to closely monitor their financial account activity, place fraud alerts, and consider placing a credit freeze.

See also: Hackers abuse Google Drive links for breaches

A third-party breach, such as in the case of ZAGG, occurs when an external organization or service provider experiences a security incident that compromises sensitive data or systems. These breaches can have a significant impact, as businesses often share critical information with third parties to streamline operations. If such a party does not have strong cybersecurity measures in place, attackers can exploit vulnerabilities, leading to data theft, operational disruptions, or reputational damage. Managing this risk involves implementing rigorous vendor verification processes, monitoring third-party activity, and ensuring compliance with security protocols.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS