Supply chain
⛓ Supply Chain
e-commerce sites that partner with Adverline Third-Party Breach (January 2019)
Primary Source ↗Incident Details
Magecart Delivered Via Advertising Supply Chain. We detected a significant increase in activity from one of the web skimmer groups we’ve been tracking.We found their malicious skimming code loaded on 277 e-commerce websites providing a variety of products and services. Figure 2: Timeline of web-skimming activities that accessed malicious domains (top); and country distribution of where they were accessed, from January 1 to January 6 (bottom) Note: Data from Trend Micro™ Smart Protection Network ™. Figure 3: The malicious code injected into compromised e-commerce websites by Magecart Group 12. Third-party company: Adverline.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Adverline
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2019-01-01 Breach occurred
- 2019-01-16 Publicly disclosed