Green Bay Packers' online store hacked to steal credit cards
Jan. 8, 2025, 8:08 p.m.
Tags
External References
Description
A threat actor breached the Green Bay Packers' official online retail store in October, injecting a card skimmer script to steal customers' personal and payment information. The attack, discovered on October 23, 2024, targeted the packersproshop.com website. The malicious code, inserted in the checkout page, could access customer data between late September and early October 2024. Affected information includes names, addresses, email addresses, and credit card details. The team disabled payment capabilities upon discovery and hired cybersecurity experts to investigate. The skimming attack utilized JSONP callback and YouTube's oEmbed feature to bypass Content Security Policy. The Packers are offering three years of credit monitoring and identity theft restoration services to affected customers.
Date
Published: Jan. 7, 2025, 5:21 p.m.
Created: Jan. 7, 2025, 5:21 p.m.
Modified: Jan. 8, 2025, 8:08 p.m.
Attack Patterns
T1505.003
T1185
T1005
T1102
T1592
T1056
T1190
T1059
Additional Informations
Retail
United States of America