logo

Avery had credit card skimmer stuck on its site for months

ID: 30f75003-3228-5e8b-9202-3448531b6950

STIX ID: report--30f75003-3228-5e8b-9202-3448531b6950

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2025-01-16

Date Updated: 2026-04-28

...
...

Avery notified customers that a JavaScript credit card skimmer was active on its e-commerce site from July 18 to December 9, 2024, potentially exposing payment card details (including CVV), names, addresses, emails, phone numbers, and purchase data for about 61,193 people; affected customers have reported fraudulent charges and phishing. The article explains that card skimmers are typically injected via CMS or plugin vulnerabilities, illustrates detection/prevention measures (antivirus, browser extensions like Malwarebytes Browser Guard, monitoring financial statements and identity/credit monitoring), and links to further guidance on responding to a data breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.