Casio UK online store hacked to steal customer credit cards
ID: e6d48986-ac07-5f07-a055-789141805f1a
STIX ID: report--e6d48986-ac07-5f07-a055-789141805f1a
Feed Name: Bleeping Computer
Casio UK's online store was compromised between 14–24 January 2025 by a two-stage web skimmer that injected a fake checkout form to capture billing and full payment card data; the skimmer fetched a second-stage payload from a Russian host, used obfuscation and XOR-based string concealment, encrypted stolen records with AES-256-CBC, and exfiltrated them to an attacker-controlled IP. JSCrambler discovered the compromise and Casio removed the malicious script within 24 hours; the attack exploited Magento vulnerabilities and a permissive Content Security Policy, and reportedly targeted 17 additional sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
