Supply chain ⛓ Supply Chain

e-commerce sites that partner with Adverline Third-Party Breach (January 2019)

📅 2019-01-01 🏢 Adverline
Primary Source ↗

Incident Details

Magecart Delivered Via Advertising Supply Chain. We detected a significant increase in activity from one of the web skimmer groups we’ve been tracking.We found their malicious skimming code loaded on 277 e-commerce websites providing a variety of products and services. Figure 2: Timeline of web-skimming activities that accessed malicious domains (top); and country distribution of where they were accessed, from January 1 to January 6 (bottom) Note: Data from Trend Micro™ Smart Protection Network ™. Figure 3: The malicious code injected into compromised e-commerce websites by Magecart Group 12. Third-party company: Adverline.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Adverline
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2019-01-01 Breach occurred
  2. 2019-01-16 Publicly disclosed