nutribullet pic

Hackers Steal Credit Card Data From NutriBullet Customers Through Magecart Attacks

The attacks, which targeted NutriBullet’s official website, were acknowledged by the company but it’s not clear whether affected customers will be notified.

Hackers were able to obtain customers’ credit card numbers, billing addresses, names and more personal information from blender manufacturer NutriBullet’s website several times over the past two months, according to a report from security firm RiskIQ.

Magecart hackers, who target online shopping cart systems using malware that “skims” credit card data from websites, were behind the attacks. The data was scraped and stored on a third-party server after the hackers were able to inject the malware on payment pages. From there, the attackers were able to sell the credit card information on the dark web, RiskIQ reported.

The hackers still have access to NutriBullet’s website infrastructure, despite the fact that the company combated the hacking by removing the malicious code each time, according to the report. NutriBullet’s chief information officer Peter Huh confirmed to TechCrunch that the intrusions had occurred and that the company had launched investigations into the incident.

However, Huh would not say whether customers would be notified about their credit card information being stolen. NutriBullet will “work closely with outside cybersecurity specialists to prevent further incursions,” Huh told TechCrunch.

Yonathan Klijnsma, the head of threat research for RiskIQ, said that the research team reached out to NutriBullet via its support channel and LinkedIn less than 24 hours after detecting an attack on Feb. 20. But as of publication of the report on March 18, the company had not responded to RiskIQ.

“The compromise is ongoing, and credit card data may still be getting skimmed, even as NutriBullet runs ad campaigns to pull in more customers,” Klijnsma wrote.

Lamar Bailey, the senior director of security research at Tripwire, said that the findings by RiskIQ show that websites, particularly those that are serving as “market fronts,” must be under strict change control. This means that any modifications to the website’s code should be approved or expected. If they are not, those changes to the code should not be allowed to go through and prompt an immediate investigation, Bailey said.

Companies’ failure to responsibly disclose cybersecurity issues or hacks also remains “a major issue,” Bailey said. He added that all sites should provide a contact page dedicated to security concerns.

“Emailing or calling support is often very frustrating and leads to a dead-end,” Bailey said. “The front line support engineers don’t understand the gravity of the situation or have no idea how to route the concerns to the correct group. We often try to contact company leadership via email or LinkedIn, but many of these attempts go unanswered because they are assumed to be spam or sales tactics.”

Photo by Your Best Digs / Flickr Creative Commons

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West
  • New Report Says 1 in 5 SMBs Would Be Forced to Shutter After Successful Cyberattack

    Small and medium-sized businesses (SMBs) play a crucial role in the U.S. economy, making up 99.9% of all businesses and contributing to half of the nation's GDP. However, these vital economic growth drivers face an escalating threat—cyberattacks that could put them out of business. Read Now

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West
  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.