Supply chain
β Supply Chain
Forbes Third-Party Breach (May 2019)
Primary Source βIncident Details
Forbes Becomes Latest Victim of Magecart Payment Card Skimmer. The web skimming script was recently found stealing payment data on the websites of Forbes Magazine as well as seven others. The payment card-siphoning Magecart group has struck again; this time injecting web-skimming scripts into the subscription website for the Forbes print magazine (as well as a slew of others over the past week). Security researcher Troy Mursch, founder of Bad Packets Report, told Threatpost that he noticed the site was compromised on Wednesday at 12:30 a.m. ET.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- not disclosed
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2019-05-01 Breach occurred
- 2019-05-16 Publicly disclosed