Supply chain
β Supply Chain
4,600 websites Third-Party Breach (May 2019)
Primary Source βIncident Details
Hackers are collecting payment details, user passwords from thousands of sites. Servers of at least seven companies compromised to deliver malicious code to thousands of sites. Hackers have breached the servers of at least seven online service providers to embed malicious code on thousands of websites, security researchers have told ZDNet. The attack is ongoing, and the malicious scripts are still live, at the time of this article’s publishing. Third-party company: Picreel and Alpaca Forms.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Picreel and Alpaca Forms
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2019-05-01 Breach occurred
- 2019-05-31 Publicly disclosed