What eCommerce Companies Have Been Hacked Recently?

The eCommerce industry as a whole is still facing an unprecedented volume of cyberattacks. Despite the National Cyber Security Alliance's warnings and recommendations, hackers continue to exploit zero-day threats in web APIs and popular eCommerce platforms. Here are some eCommerce platforms that have recently been hacked:

eCommerce Sites Under Volusion

Hackers breached Volusion's Google Cloud environment in early October 2019. Once inside, the hackers installed malicious skimmer code on over 6,500 Volusion stores.

Magecart, a group of hackers who had previously attacked British Airways, Newegg, and Ticketmaster, infiltrated their platform. The Volusion hack ultimately resulted in the theft of payment information from Volusion merchant websites.

WordPress eCommerce Sites

As an open-source platform, it is unsurprising that WordPress is frequently targeted by hackers. WordPress accounted for 90% of all hacked CMS (content management system) websites in 2018.

The majority of WordPress website hacks were caused by security flaws in plugins and themes, misconfiguration issues, and a lack of maintenance and updates. However, only 36% of the hacked WordPress sites were running an outdated version, suggesting that this was not the primary cause.

Companies Using Magento 2

Companies that used Magento 2 were the targets of a hack attempt in March 2019, in which hackers exploited a SQL injection vulnerability in the Magento CMS. This flaw could have been exploited to install payment card skimmers, which would steal credit card information from any customer who made a payment on a vulnerable Magento 2 store.

Fortunately, Magento developed a patch that merchants could use to protect their sites from this exploit. Again, because Magento is an open-source eCommerce platform, it is inherently more difficult to secure than SaaS competitors.

