Keeper group hacked 570 online stores in three years

Tomcat

Professional
Messages
2,695
Reaction score
1,072
Points
113
The cybercriminal group Keeper has carried out about 570 hacks of e-commerce sites over the past three years. The attackers hacked into the backends of online stores, changed their source code, and injected malicious scripts that steal payment card data entered by customers into the order form.

According to experts from the Gemini Advisory company, Keeper began its criminal activities at least in April 2017 and currently remains active as well. The experts were able to track the activities of the group, because Keeper used the same control panels for internal servers, where they collected the stolen payment card details of customers of the hacked stores. The specialists gained access to the addresses of the server panels, the malicious URLs used to host the software infrastructure, as well as a list of hacked online stores into which Keeper injected its scripts.

Almost 85% of the 570 hacked stores ran on Magento e-commerce management platform.

According to experts, the criminals did not properly protect one of their internal panels, where hackers sent stolen payment card data. Cybercriminals managed to steal about 184 thousand payment card data from July 2018 to April 2019. For the entire time of their activity, the cybercriminals managed to steal about 700 thousand payment card data. According to experts, Keeper has earned over $ 7 million for her criminal actions.
 
Top