Packers_Pro_Shop

Thousands of credit cards stolen in Green Bay Packers store breach

Teilen:

​American football team Green Bay Packers says cybercriminals stole the credit card data of over 8,500 customers after hacking its official Pro Shop online retail store in a September breach.

In breach notification letters sent to affected individuals this week, the National Football League (NFL) team said it immediately disabled all checkout and payment capabilities after being notified on October 23 that the packersproshop.com website was breached.

While the letters didn’t share the number of impacted customers impacted, the football team said in documents filed with Maine’s Attorney General on Monday that the incident affected 8,514 people.

A follow-up investigation found that the attackers injected a credit card stealer in the store’s checkout page to harvest personal and payment information. However, the Packers said the attacker couldn’t intercept information from any payments made using gift cards, a Pro Shop website account, PayPal, or Amazon Pay.

“We also immediately required the vendor that hosts and manages the Pro Shop website to remove the malicious code from the checkout page, refresh its passwords, and confirm there were no remaining vulnerabilities,” the Packers’s Director of Retail Operations Chrysta Jorgensen explained.

“Based on the results of the forensic investigation, on December 20, 2024 we discovered that the malicious code may have allowed an unauthorized third party to view or acquire certain customer information entered at the checkout that used a limited set of payment options on the Pro Shop website between September 23-24, 2024 and October 3-23, 2024.”

The breach impacted information entered on the Pro Shop website at checkout, including names, addresses (billing and shipping), email addresses, credit card types and numbers, card expiration dates, and credit card verification numbers (CVVs).

The Packers has yet to share how the threat actor hacked its Pro Shop website; however, Dutch e-commerce security company Sansec, which spotted the Packers store breach in early October, found that the card skimming attack used YouTube’s oEmbed feature and a JSONP callback to bypass the Content Security Policy (CSP).

​”In this attack, a script was injected from https://js-stats.com/getInjector. This script harvested data from input, select, and textarea fields on the site, exfiltrating the captured information to https://js-stats.com/fetchData,” Sansec said in a December 31 report.

The NFL team offers affected people three years of identity theft restoration and credit monitoring services through Experian and advises them to track their account statements for fraudulent activity.

Anyone observing identity theft or fraud attempts should report them to their bank and the appropriate authorities, including the Federal Trade Commission (FTC) and the state attorney general.

In September 2022, the San Francisco 49ers also notified over 20,000 individuals that attackers stole their personal information (including Social Security numbers) in a February 2022 breach later claimed by the Blackbyte ransomware gang.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:38 pm, März 16, 2025
Wetter-Symbol 8°C
L: 7° | H: 9°
wenige Wolken
Luftfeuchtigkeit: 57 %
Druck: 1025 mb
Wind: 10 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:12 am
Sonnenuntergang: 6:06 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 9°°C 0 mm 0% 11 mph 77 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 10 mph 89 % 1029 mb 0 mm/h
Di. März 18 9:00 pm
Wetter-Symbol
4° | 10°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 7 mph 79 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 10°°C 0 mm 0% 11 mph 52 % 1025 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 8 mph 60 % 1025 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 77 % 1027 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 84 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 89 % 1027 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 81 % 1028 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 7 mph 66 % 1029 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 52 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,955.70
-1.54%
Ethereum(ETH)
€1,727.52
-2.24%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.13
-4.48%
Solana(SOL)
€119.67
-2.52%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.154856
-3.21%
Shiba Inu(SHIB)
€0.000012
0.29%
Pepe(PEPE)
€0.000006
-4.58%
Peanut das Eichhörnchen(PNUT)
€0.189019
20.47%
Nach oben scrollen