Supply chain
⛓ Supply Chain
Macy's Third-Party Breach (November 2019)
Primary Source ↗Incident Details
Macy’s suffers online Magecart card-skimming attack, data breach. The department store detected malicious code in its online payment portal. Macy’s has announced a data breach caused by Magecart card-skimming code being implanted in the firm’s online payment portal. In a letter issued to customers, the company says that it was alerted to the security incident on October 15, and the Macy’s team quickly found that card-skimming script had been injected into two pages on the Macy’s website.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- not disclosed
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2019-11-01 Breach occurred
- 2019-11-19 Publicly disclosed