Attention, lockdown DIY fans: UK hardware flinger Robert Dyas had credit card data and more skimmed from website
- Reference: 1587562814
- News link: https://www.theregister.co.uk/2020/04/22/robert_dyas_card_skimmer/
- Source link:
Between 7 and 30 March a card skimmer was present on Robert Dyas' payment processing page, the chain admitted in an email sent to affected customers that was seen by The Register .
"We became aware on 30 March 2020 that malicious software (malware) had been uploaded on to our ecommerce website by an external third party, which was immediately blocked by our IT Security team," said the email.
Stolen data is said to include "personal and credit/debit card details, along with names and addresses of customers." Nobody's Robert Dyas password was stolen, though that will be the least of the affected people's worries.
From the description it is plain that card-skimming malware was present. We have asked the Theo Paphitis-owned chain for further details and whether the infection was the infamous Magecart malware.
Jake Moore of infosec biz Eset dryly commented to The Register : "This is by no means the perfect timing to have a card skimmer to be hidden and operating on your site during a time when online sales are going through the roof in most industries."
He added: "For those affected it may even be a double blow as to when they understand the full potential and impact it may have on their finances. Of course, these customers should contact their banks for further details and added support but this shouldn't be taken lightly. Although no passwords seem to be taken I would suggest they change it as a matter of procedure in case it further comes out that more data was in fact compromised."
A common attack vector for these types of compromises is targeting of the so-called "supply chain": compromise of the third party website that serves up elements of the card payment page. One method is for a third party to be breached so malicious Javascript can be injected into the payment page, as [1]Forbes magazine discovered last year .
Back in March – ironically – US box brand Tupperware was struck with a similar infection that [2]used a malicious PNG image file along with steganographic techniques to hide the compromise.
Robert Dyas is owned by Dragon's Den telly star Theo Paphitis. It has 94 shops across the south of the UK and in Christmas 2018 [3]boasted that online sales grew by 45 per cent over the previous 12 months, having turned over £131.8m and made gross profits (EBITDA) of £1.6m. In the previous year it [4]made a £780,000 loss .
A spokesperson for Robert Dyas said: “As soon as we became aware of the presence of malicious software deployed by an external third party on our ecommerce site, we took immediate action to remove it. We are confident this issue has been fully resolved and the website has been safe for use since 31st March.
“We informed our Merchant Service Provider - who manages all our credit or debit card payments online on our behalf – and the relevant card schemes, who inform the payment card providers, which include banks. We are in touch with approximately 20,000 affected customers and are recommending they also contact their bank or card provider and follow their recommendations as a precaution.
“We are working with the relevant authorities in response to the incident and have appointed a Payment Card Industry Forensic Investigator to carry out an independent investigation. We are deeply sorry for the concern and inconvenience this illegal activity has caused some of our customers.”
The spokesperson added that "unfortunately, the perpetrators did gain access to the long card number, expiry date and security (CVV) code."
Ouch. ®
Sponsored: [5]Legacy Modernization: Finding Your Way With Low-Code
[1] https://www.theregister.co.uk/2019/05/16/forbes_magecart_infection/
[2] https://www.theregister.co.uk/2020/03/25/tupperware_dot_com_credit_card_skimmer_malwarebytes/
[3] https://www.insightdiy.co.uk/news/robert-dyas-reports-63-rise-in-2019-revenue/7994.htm
[4] https://www.retailgazette.co.uk/blog/2019/01/robert-dyas-swings-loss-amid-online-investment/
[5] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936
Credit Card Skimmers
If you would like to see what a typical card skimmer looks like, check out the webpage source of:
https://www.antiquesilverspoons[.]co[.]uk/
(starting at line 1098)
This site has been infected for a long time and they don't respond to email.
I believe the C&C of the skimmer is also sinkholed by a well-known security outfit to render it somewhat benign.
Well balls
Ordered twice from Robert Dyas in March, where is my bloody we care about you email as I havent had one yet!
Re: Well balls
Haven't had the opportunity / misfortune to order from them online, but I find Dyas to be one of the more useful shops on the high street (I don't drive).
'Skimmer' and 'CCV' = a website vuln, not backend?
I'm just seeking education here. The difference would be whether over the counter sales / card payments are affected.
Re: 'Skimmer' and 'CCV' = a website vuln, not backend?
Yes, a skimmer means somebody got something into their website that reported your details to them (as well as to Robert Dyas). Similar to a skimmer over the slot of a cash machine which reads your cards as they are used. Doesn't stop the data being used for the original purpose, but separately reads it.
Typically CCV numbers are not stored by people, so if they are exposed then that would show either they have stored them in their DB (which is very naughty) or that somebody skimmed them on the way.
Hmm
"We became aware on 30 March 2020 that malicious software (malware) had been uploaded on to our ecommerce website by an external third party, which was immediately blocked by our IT Security team"
malware... uploaded... immediately blocked. Sounds good, until you read more carefully.