Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages
Overview
Researchers have uncovered a significant web skimming campaign that has been stealing credit card information from online checkout pages since January 2022. This attack primarily targets major payment networks, including American Express, Mastercard, and UnionPay, affecting enterprise organizations that use these payment services. The skimming malware is designed to capture sensitive payment information as users enter it during online transactions. As a result, customers of these affected enterprises may be at risk of fraud and identity theft. It’s crucial for businesses to enhance their security measures and for users to monitor their financial statements for any suspicious activity.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, UnionPay
- Action Required: Businesses should enhance their security measures, including implementing web application firewalls, regularly monitoring for malware, and educating users about safe online shopping practices.
- Timeline: Ongoing since January 2022
Original Article Summary
Cybersecurity researchers have discovered a major web skimming campaign that has been active since January 2022, targeting several major payment networks like American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay. "Enterprise organizations that are clients of these payment providers are the most likely to be impacted," Silent Push said in a report published today.
Impact
American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, UnionPay
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since January 2022
Remediation
Businesses should enhance their security measures, including implementing web application firewalls, regularly monitoring for malware, and educating users about safe online shopping practices.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.