WebsiteGear Logo Log In
New User? Sign Up
About | Contact | FAQ
  Home News Website Related Website Revenue Saturday, April 25, 2026 
Add Press Release News | News Feeds Feeds | Email This News Email


Cyberpion Reveals Research Showing How Magecart is Poised to Exploit Some of the World's Biggest Brands
Thursday, November 18, 2021

Data skimming technique has become an unstoppable threat

KIRKLAND, Wash. and TEL AVIV, Israel, Nov. 10, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research at Black Hat Europe 2021 revealing that some of the world's largest companies across retail, banking, healthcare, energy and many other sectors, including Fortune 500, Global 500 and governments are failing to prevent Magecart attacks.

The research analyzed more than 30,000 Magecart vulnerabilities over the last two years and found significant weaknesses in modern security platforms and processes to identify and mitigate Magecart exploits. More than 10,000 Magecart vulnerabilities are still active. There were also severe lapses in enterprises disclosing security vulnerabilities or exploits occuring along their digital supply chains to their customers, ultimately placing all connected organizations at severe risk of a critical breach.

Magecart is the common name for a style of cyber attack in which hackers compromise third party code (typically Javascript that runs in browsers) to steal, or scrape, information such as credit card data from web-applications (e.g. online checkout software) or websites that incorporate the code. Web skimming continues to be a real threat to online merchants and shoppers with attacks severely impacting organizations including British Airways and Ticketmaster in 2018, Forbes magazine in 2019, plus local US government portals and messaging service Telegram 2020.

Companies can discover if they have been the target of a Magecart attack or affected by Magecart vulnerability by visiting this website.

"Our conclusion from the analysis is that as of today, organizations fail to face Magecart threats and detect the vulnerabilities and exploits that hackers leverage to conduct these attacks," said Cyberpion CEO Nethanel Gelernter. Victims are often the last to know as it's only later that organizations find that their data was sold or exploited, with the problem extending beyond any single vendor or client relationship. For enterprises in particular, Magecart attacks pose a significant challenge because it is problematic to set up a solution at scale."

Highlights from the research include:

    --  At least one of the top five enterprises in many verticals - retail,
        insurance, financial services, pharma, media, security and others - were
        found to be vulnerable or abused.
    --  More than 1000 online shops are vulnerable, exposing their customers to
        skimming. Some of the most popular international newspapers were found
        to be vulnerable, often via their home page
    --  Lesson not learnt: The exact vulnerability that led to Magecart's data
        breach on British Airways could easily be replicated on the sites of
        other global aviation companies, despite being a simple fix.
    --  Some vulnerable or abused companies do use anti-Magecart solutions, but
        these could be bypassed.
    --  Vendor infrastructure exposes many other connected organizations to
        Magecart, yet vendors often fail to inform them about it early enough in
        order for so they could take preventative action to be taken. In one
        case, a leading online advertising network affected 15 global insurance
        brands alongside hundreds of other enterprises.

About Cyberpion
Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.turner@si14global.com

View original content:https://www.prnewswire.com/news-releases/cyberpion-reveals-research-showing-how-magecart-is-poised-to-exploit-some-of-the-worlds-biggest-brands-301420119.html

SOURCE Cyberpion



Email This News Email | Submit To Slashdot Slashdot | Submit To Digg.com Digg | Submit To del.icio.us Del.icio.us | News Feeds Feeds

RELATED NEWS ARTICLES
Nav The New Identity Theft Crisis: AI Scams, Child Victims, and Credit Damage Are All Spiking | Jan 22, 2026
Nav AllSci Launches Hypothesis Publishing: A Seamless Way to Share, Connect, and Advance Scientific Ideas | Jan 22, 2026
Nav Canadian Fintech Tuhk Inc., Founded by Ethoca and NuData Security Veterans, Raises US$6 Million Seed Round Led by FINTOP, with Lloyds Banking Group and Capital One Ventures | Jan 22, 2026
Nav Darwin CX Caps a Banner Year with AI Launch, Sold-Out Events, and Industry Book Launch | Jan 22, 2026
Nav Fintech Startup BON Credit Secures $3.5 Million In Funding | Jan 22, 2026
Nav PayDo Launches Unified Payment Infrastructure Suite for Digital Businesses | Jan 22, 2026
Nav Nudge Security Unveils Industry's Most Comprehensive AI Security Governance Platform | Jan 22, 2026
Nav IoTeX Publishes MiCA-Compliant Whitepaper for IOTX, Enabling EU-Wide Alignment Under the New Regulatory Framework | Jan 22, 2026
Nav Gametime Launches "12 Days of Gametime" Holiday Giveaway in Partnership with Barstool Sports | Jan 22, 2026
Nav TSX Venture Exchange Market Data Now Available Across Over 40 Blockchains via Chainlink | Jan 22, 2026
NEWS SEARCH

FEATURED NEWS | POPULAR NEWS
Submit News | View More News View More News