- Data breach of online retailer.
- Credit card details among exposed credentials.
- Company registers incident in two states.
Wherever online there’s money or data, there are hackers determined to take it. The latest victims are over 200,000 customers of US-based SelectBlinds, whose website was hacked with malware, code that exfiltrated customers’ names, addresses, phone numbers, credit card details, usernames and passwords.
SelectBlinds filed data breach notifications in the states of California and Maine that detailed its discovery of the malware at the end of September this year, and stated the malicious code had been present on the SelectBlinds website since early January 2024.
Customers using the site’s checkout feature to pay for SelectBlinds’s goods had their details, including card expiry dates and CVV security codes, scraped by the malware’s owners.
SelectBlinds has said it’s now removed the malware from its site, and is making all users reset their passwords at the point of login.
Credit-card skimming attacks are very common, with some high-profile names affected in the past, including the ubiquitous Ticketmaster, Vision Direct, Chinese marketplace store SHEIN, and British Airways.
The different states in the US each have their own data breach notification rules, with variations in time-frames in which notification of breach has to be registered, the types of data compromised that have to be detailed, and the specific body responsible for collating notifications. For many retailers whose cybersecurity methods may not be as good as they perhaps should be, the varied requirements and stipulations present a complex framework that needs to be navigated.
Not only is reporting a breach complex, but the chain of applications and services that make up an e-commerce facility are often unique, and therefore present no ‘standard method’ to protect a retailer and its customers. With many dozens (or even thousands, if software dependencies are counted individually) of software components making up a retailer’s payment facilities, protecting against hackers searching for a chink in the armour is a tough call.
The best most organisations can hope for, beyond patching and proper investment in the latest anti-hacking methods, is reliable and detailed monitoring of all their online services. The expertise required to establish and maintain such a monitoring facility is, unfortunately, as specialised as cybersecurity. But monitoring for anomalous behaviour and acting appropriately in a timely manner will at least help ensure as few customers as possible have their financial and personal data compromised.
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first computer with dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.