Hackers Steal Credit Cards from Online Retailer’s Own Checkout

Hackers Steal Credit Cards from Online Retailer’s Own Checkout

Attackers injected 15 lines of Javascript code into Newegg.com’s web store, forwarding payment information to their own server.

Popular online tech retailer Newegg scrambled to shut down an attack on their web store this week, after learning hackers had been poaching customer payment data from their own website since August.

Incident response firm Volexity discovered the card skimming malware and reported it to Newegg, who removed the offending code on Tuesday. The attackers, known as “Magecart,” had injected Javascript code into the payment form page. The code watched for a click on the payment button, then submitted the entire form to a remote server, the action disguised as a credit card authentication step in the payment process.

The code worked for both PC and mobile customers, but it is unknown if mobile customers were affected by the breach. In an email to customers, Newegg’s chief executive said the company had not yet determined which customers were at risk.

This comes on the heels of two other attacks, both carried out by Magecart in a very similar fashion. In June, ticket distribution giant Ticketmaster UK faced a hack taking advantage of a customer support chat bot, and then in early September, British Airways reported that customers who made bookings in late August through 5 September had their information compromised.

The code used to skim credit cards was almost identical in all three instances, as reported by a threat researcher at RiskIQ, a cybersecurity firm.

Newegg reassured customers that the breach had been fully shut, and their website was operational once again.

About the Author

Jordan Lutke is an intern with 1105 Media.

Featured

  • 2025 Gun Violence Statistics Show Signs of Progress

    Omnilert, a national leader in AI-powered safety and emergency communications, has released its 2025 Gun Violence Statistics, along with a new interactive infographic examining national and school-related gun violence trends. In 2025, the U.S. recorded 38,762 gun-violence deaths, highlighting the continued importance of prevention, early detection, and coordinated response. Read Now

  • Big Brand Tire & Service Rolls Out Interface Virtual Perimeter Guard

    Interface Systems, a managed service provider delivering remote video monitoring, commercial security systems, business intelligence, and network services for multi-location enterprises, today announced that Big Brand Tire & Service, one of the nation’s fastest-growing independent tire and automotive service providers, has eliminated costly overnight break-ins and significantly reduced trespassing and vandalism at a high-risk location. The company achieved these results by deploying Interface Virtual Perimeter Guard, an AI-powered perimeter security solution designed to deter incidents before they occur. Read Now

  • The Evolution of ID Card Printing: Customer Challenges and Solutions

    The landscape of ID card printing is evolving to meet changing customer needs, transitioning from slow, manual processes to smart, on-demand printing solutions that address increasingly complex enrollment workflows. Read Now

  • TSA Awards Rohde & Schwarz Contract for Advanced Airport Screening Ahead of Soccer World Cup 2026

    Rohde & Schwarz, a provider of AI-based millimeter wave screening technology, announced today it has won a multi-million dollar award from TSA to supply its QPS201 AIT security scanners to passenger security screening checkpoints at selected Soccer World Cup 2026 host city airports. Read Now

  • Brivo, Eagle Eye Networks Merge

    Dean Drako, Chairman of Brivo, the leading global provider of cloud-native access control and smart space technologies, and Founder of Eagle Eye Networks, the global leader in cloud AI video surveillance, today announced the two companies will merge, creating the world’s largest AI cloud-native physical security company. The merged company will operate under the Brivo name and deliver a truly unified cloud-native security platform. Read Now

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.