Supply chain β›“ Supply Chain

4,600 websites Third-Party Breach (May 2019)

πŸ“… 2019-05-01 🏒 Picreel and Alpaca Forms
Primary Source β†—

Incident Details

Hackers are collecting payment details, user passwords from thousands of sites. Servers of at least seven companies compromised to deliver malicious code to thousands of sites. Hackers have breached the servers of at least seven online service providers to embed malicious code on thousands of websites, security researchers have told ZDNet. The attack is ongoing, and the malicious scripts are still live, at the time of this article’s publishing. Third-party company: Picreel and Alpaca Forms.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Picreel and Alpaca Forms
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2019-05-01 Breach occurred
  2. 2019-05-31 Publicly disclosed