This alert may not be shared outside your organization, Do Not Repost or send, place on other websites, List servers, or send to others via email, including other associations or parties.  Members and Law enforcement use only. Contact us for any permissions.  To do otherwise will result in the loss of membership.

Complete Story
 

11/18/2020

Magecart Hits Macy's: Retailer Discloses Data Breach

Dark Reading

Macy's has confirmed a data breach following the discovery of Magecart malware on its checkout page and wallet page, which is accessed through My Account, the retailer reports.

In a letter to customers, the retailer says it was alerted to a "suspicious connection" between Macy's and another website on October 15. An investigation determined malicious code was added to two macys.com web pages on October 7. The code was "highly specific" and only allowed a third party to capture data submitted by customers on the wallet page and checkout page if credit card data was entered and "place order" was clicked. Its teams removed the code on October 15.

During the week that the malicious code was live, Macy's reports cybercriminals may have potentially accessed customer data including first name, last name, address, city, state, ZIP code, phone number, email address, and their payment card's full number, security code, and month and year of expiration if this data was typed into either of the affected web pages.

Read more...

Printer-Friendly Version


Resources

Alerts

The FRPA alert system distinguishes us from other groups by gathering and providing information to law enforcement, retailers AND financial institutions.

more information
Resources

Resources

Your electronic library to help in fighting financial fraud for all of our partners.

more information