logo

Casio UK online store hacked to steal customer credit cards

ID: e6d48986-ac07-5f07-a055-789141805f1a

STIX ID: report--e6d48986-ac07-5f07-a055-789141805f1a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-02-03

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Casio UK's online store was compromised between 14–24 January 2025 by a two-stage web skimmer that injected a fake checkout form to capture billing and full payment card data; the skimmer fetched a second-stage payload from a Russian host, used obfuscation and XOR-based string concealment, encrypted stolen records with AES-256-CBC, and exfiltrated them to an attacker-controlled IP. JSCrambler discovered the compromise and Casio removed the malicious script within 24 hours; the attack exploited Magento vulnerabilities and a permissive Content Security Policy, and reportedly targeted 17 additional sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.