Cybercriminals managed to bypass the security measures of the Lime Crime cosmetics website and infected the web server with malware that steals customers' payment information

The company discovered the incident after experts conducted an investigation. It was found that only credit card purchases were affected and that the data of customers using PayPal was not affected by the incident. However, their log-in credentials were exposed during the incident and the company has informed them by letter.
It appears that the malware was planted on the server and was active between October 4, 2014 and February 15, 2015. Every transaction between this time frame is believed to have been intercepted.
According to information from Lime Crime, the breach was discovered on February 11, 2015.
The data stolen by the malware includes names, addresses, log-in credentials, payment card account numbers, card expiration date, and CVV (card verification value).
According to the Payment Card Industry Data Security Standard (PCI DSS), merchants must not store CVV codes in their infrastructure.
Lime Crime's measures to resolve the issue include taking the website offline to perform cleanup procedures and prevent further theft of personal information. In addition, the company is moving to a different e-commerce platform that is certified and PCI compliant.
Any user who has made a purchase on the website during the aforementioned period should check their credit and debit cards for unusual activity that may be indicative of attempted fraud.
The company also used social media profiles on Facebook and Twitter to inform its customers about the incident.
In addition, the company has enforced password resets for all of its customer accounts and advises users to rely on unique passwords for each online service they connect to.
The identity protection service is being offered free of charge, for one year, by Lime Crime to affected customers, who can call the US credit reporting agency Experian and report the illegal transactions on their cards.
