Separator

Hackers & Attackers are 'Formjacking' Thousands of Website to Steal User Data Every Month

Separator
Hackers & Attackers are 'Formjacking' Thousands of Website to Steal User Data Every Month

CEO Insights Team

According to a new report from security research firm Symantec, cyber criminals and other hacker syndicates are carrying out ‘formjacking’ attacks at an increasing rate. It has evolved and become stealthier in the last couple of months, where attackers are now injecting malicious codes into websites to steal more than just credit card information.

In case you aren’t aware about it, formjacking is a type of cyber attack where hackers inject malicious JavaScript code into a webpage form - most often a paymet page form. This implanted malicious JavaScript code alters the behavior of the targeted web form or process on the compromised website to surreptitiously steal payment card data and other personal information in the background. As a continuation from Symantec’s ISTR 24 report, Symantec has launched an in-depth analysis on formjacking attacks that are frequently in the news highlighting how websites and consumers have been affected in the last one year.

Symantec has seen a major uptick in formjacking attacks recently, with publicly reported attacks on the websites of companies including Ticketmaster, British Airways, Feedify, and Newegg by a number of groups summarized as Magecart being the most prominent examples. “Each month we discover thousands of formjacking infected websites, which generate millions of dollars for the cyber criminals,” states Candid Wueest, Principal Threat Researcher, Symantec.

As per the report, India ranks third with 5.7 percent of global detections. Symantec highlights in the report that they have blocked more than 2.3 million formjacking attacks globally in Q2/2019. In the first six months of 2019, users in the US were by far the most exposed to formjacking attacks with 52 percent of all global attacks,

Each month we discover thousands of formjacking infected websites, which generate millions of dollars for the cyber criminals



up from 33 percent in 2018.

With such sophisticated attacks, website owners should be aware as this could generate attached costs for affected organizations resulting from things like customer notification processes and possible fines. In addition to the cost of the data breach, there is also a loss of customer trust and damage to the organization’s brand reputation. This can be especially devastating for online stores which heavily depend on customer orders.

“Consumers often don’t notice that they have become a victim to a formjacking attack as it can happen on a trusted online store with the HTTPS padlock intact. Therefore, it is important to have a comprehensive security solution that can protect you against Formjacking attacks,” adds Wueest.

With sophisticated and stealthy attackers like Magecart, the solution for being safe for website owners is to use several different methods to protect their web presence from formjacking. A baseline standard should be to harden any server or service used for hosting the website. This includes scanning local files for any malicious scripts and implementing change control measures to validate and authorize all changes - similar to classic defacement prevention. They must monitor behavior of all activity on a system that can also help identify any unwanted patterns and allow you to block a suspicious application before any damage can be done.

Formjacking attacks are increasing in volume. The reason for this is twofold: they are difficult to detect for end users and can be very lucrative for cyber criminals. In addition, the attacks are quite simple to conduct, and the injected malicious JavaScript is not difficult to create. Formjacking is showing no signs of disappearing any time soon. Therefore, operators of online stores need to be aware of the risk and protect their online presence.

In Print




Most Viewed

From 'Volume' to 'Value': India Inc's Mantra to Capture the Global Pharmaceutical Market A Fight Back from Arabian Peninsula When will The Tech Industry’s Lay-off Season End? The Story of a Broken Trust Technology Key To Global Travel Recovery What To Keep In Mind When Selecting The Right Air Compressor For Replacement? The Best Way to Recover from Ransomware Attacks How Tensions Grew Worse between Elon Musk and Donald Trump New Markets, New Brands: Tailoring Success for Different Places Empowered Leadership in a Changing Legal World Four Key Steps For Healthcare Providers To Combat Ransomware Turning Vision into Value: How I Built Purposeful Digital Ecosystems in the UK Dave Thomas: A Role Model for Aspiring Entrepreneurs, Philanthropists Digital Analytics Products: How Organizations Choose Them Kelly Ortberg: The New Boeing CEO Who is Already on the Headlines India’s Military Alacrity for Modern Threats Reshma Saujani: Reshaping Social Attitudes Around Gender and Tech India is Manifesting Leadership in Drone Technology 5 Greatest Role Models in the Manufacturing Industry Creating a Stronger Ecosystem by Fixing the Nuts & Bolts of the Economy Microsoft for India: Making India for Future Ready India's UPI Launch in France Opens Gateway to Global Fintech Power Tim Cook Nears Retirement, Who Will Take Over Apple's Throne? Soil Based Microbial Fuel Cells Could Protect the Environment from Flammable Chemicals The mantra of Academic Collaboration Echoes on this Teachers’ Day Indian semiconductor Boom Has Abundant Room for SME-preneurs Indian Healthcare Ecosystem is Hosting a Multidimensional Paradigm Shift Being a True Republic: You Got to Love this New, Powerful India Qatar World Cup 2022 Might Be Over, But Arabian Peninsula’s Sports Dream is Just Beginning Reimagining the UK–India Partnership in a Changing Global Order These Schemes Will Facilitate Women Entrepreneurs Decarbonization & Sustainable Future: Technology & What it can Do?


🍪 Do you like Cookies?

We use cookies to ensure you get the best experience. Read more…