Post Now
Image

Eggfree Cake Box disclosed that it had suffered a data breach where the threat actors hacked their website and compromised their personal information.

  • Cake Box sent emails to its customers disclosing the data breach.
  • The hackers stole customer information, including credit card details.

Eggfree Cake Box disclosed that it had suffered a data breach where the threat actors hacked their website and compromised their personal information.

Cake Box learned of the breach on April 7, 2020, when they were warned by their then-payment processing provider, Global Payments, about the breach.

The firm disclosed the data breach in emails sent to customers this week stating that their website was hacked in 2020 to include malicious scripts that stole customer data.

Part of the Cake Box data breach notification; Source @BleepingComputer

“We immediately launched a thorough investigation of our systems in response and, with the help of experienced third-party security specialists, determined that an unauthorised third party had indeed recently gainedaccess to the Cake Box website and placed certain malware on it", reads the data breach notification.

Using this malware, the third party could copy certain information provided by the customers when making purchases from the website. The company subsequently made aware that, in certain instances, this data has been used to make fraudulent purchases.

When customers made purchases on the site while infected, these malicious scripts sent the first name and surname, postal address, email address and payment card data, including the three-digit CVV code, to a remote server controlled by the attackers.

According to BleepingComputer, the breach appears to be a MageCart attack.

In MageCart attacks, threat actors hack an e-commerce site and add malicious scripts to their payment confirmation pages.

If you have received a notification about the data breach being a Cake Box customer, you should keep track of your current and past transactions so that no fraudulent charges are present.

For the latest cyber threats and the latest hacking news please follow us on FacebookLinkedin, and Twitter.

You may be interested in reading: How to Survive the COVID Time Cyber ​​Security Threats?