News: 1649068151

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Emma Sleep Company admits checkout cyber attack

(2022/04/04)


Emma Sleep Company has confirmed to The Reg that it suffered a Magecart attack which enabled ne'er-do-wells to skim customers' credit or debit card data from its website.

Customers were informed of the breach by the mattress maker via email in the past week, with the business saying it was "subject to a cyber attack leading to the theft of personal data" but not specifying in the message when it discovered the digital burglary.

"This was a sophisticated, targeted cyber-attack on the checkout process on our website and personal information entered, including credit card data, may have been stolen, whether you completed your purchase or not," the email to customers states.

[1]

The company confirmed to us it was a Magecart attack via the ubiquitous Adobe Magento e-commerce platform.

[2]

[3]

"This Magecart attack, which affected customers in 12 countries, involved a malicious piece of code that was added to checkout pages which would skim card data from within a user's browser. The attack was highly targeted, and the attacker created copy-cat URLs tailored to our environment."

The spokesperson said they could confirm that the "platform was kept up to date with all relevant security fixes."

[4]

In a classic Magecart attack, such as the one that [5]exposed 40 million British Airways customers' data in 2018 (and for which it was [6]fined £20m/$26m ), dodgy folk use skimming techniques to pilfer punters' credit or debit card data.

Operatives get access to a site, either directly or via third-party services, and inject malicious JavaScript which then nabs the information as it is input.

Emma Sleep Company confirmed that its security measures had been "circumvented in a technically advanced way by how the Javascript code was implemented and loaded dynamically from the attacker's server and through highly sophisticated evasion techniques to avoid detection, as well as elaborate countermeasures to (unsuccessfully) prevent analysis, which is why the technology we had in place to keep track of scripts added to the page did not detect it."

[7]

It added: "Additional capabilities to detect such attacks have now been deployed. We are also in the process of implementing new CORS and CSP headers."

In February this year, Adobe issued [8]two out-of-bounds [9]patches in a single week when critical security bugs affecting its Magento/Adobe Commerce product emerged, with the vendor warning the vulns were being actively exploited.

Emma Sleep Company's CEO, Dennis Schmoltzi, confirmed in a statement to The Register that the cyber-attack "on the checkout process on our website" had occurred "between 27 January 2022 and 22 March 2022."

Schmoltzi added: "Personal customer information, including credit card data, was stolen. While we never process or store credit card data ourselves, the type of attack was redirecting information as it was typed into form fields in the browser of the user. As of today, we are not aware of any successful abuse of this data."

"As soon as we became aware of this attack, we took immediate action to remove the threat and ensure the security of data, launched a full investigation, and reported this to the relevant authorities, including the police. We also directly contacted all those customers who may have been affected."

CTO Andreas Westendörpf was [10]interviewed talking about scaling up the company's Magento e-commerce solution in January. He told retail digitalization trade mag Location Insider (translated from German): "Magento has been continuously adapted and expanded over the years. In addition, more and more solutions were added that go in the direction of ERP and supply chain."

Patch now Needless to say, if you are looking after an Adobe/Magento shop and haven't yet patched, the time to do so is now. The relevant Adobe security bulletin is [11]here .

Currently there is "no evidence" personal or payment data has been abused in the wild, the company said to customers in the email. Nevertheless, it advised them to contact their banks or credit card provider and "follow their advice," and check for unusual or suspicious activity from the date of visiting the checkout page on Emma's website.

One customer that shared the email on the condition of anonymity said: "Apparently getting a good night's sleep means you now might not get a good night's sleep."

[12]Ticketmaster: We're not liable for credit card badness because the hack straddled GDPR day

[13]UK Ministry of Defence takes recruitment system offline, confirms data leak

[14]British Airways fined £20m for Magecart hack that exposed 400k folks' credit card details to crooks

[15]Boat biz breaches itself: Brittany Ferries 'fesses up to leaks caused by routine website update

This isn't the finest moment for a rapidly expanding business that turned over [16]$731m in 2021 , up 59 per cent year-on-year – its eight fiscal year since being founded. It designs and makes "all-foam bed-in-a-box mattresses," a commodity that was seemingly in demand as people looked to make their homes more comfortable while under extended COVID lockdowns.

The German company operates in 18 countries including the US and China, and says it has won 75 awards for its sleep products.

Emma Sleep Company noted that it could answer all of our questions while police investigations continue.

A spokesperson at the ICO - Britain's data watchdog - said: "People have the right to expect that organisations will handle their personal information securely and responsibly.

"Emma, the sleep company has made us aware of an incident and we are assessing the information provided." ®

Get our [17]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YksWMUEFWu@icQbScPTMIQAAAMU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YksWMUEFWu@icQbScPTMIQAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YksWMUEFWu@icQbScPTMIQAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YksWMUEFWu@icQbScPTMIQAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2018/09/06/british_airways_hacked/

[6] https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YksWMUEFWu@icQbScPTMIQAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/02/16/adobe_chrome_patch/

[9] https://www.theregister.com/2022/02/18/adobe_magento_patch/

[10] https://locationinsider.de/emma-the-sleep-company-wie-sich-der-d2c-champion-technologisch-neu-aufstellt/

[11] https://helpx.adobe.com/security/products/magento/apsb22-12.html

[12] https://www.theregister.com/2020/11/25/ticketmaster_gdpr_fine_chicanery/

[13] https://www.theregister.com/2022/03/24/ministry_of_defence/

[14] https://www.theregister.com/2020/10/16/british_airways_ico_fine_20m/

[15] https://www.theregister.com/2021/11/10/brittany_ferries/

[16] https://www.prnewswire.com/news-releases/emma-reports-record-sales-and-accelerates-international-growth-301494950.html

[17] https://whitepapers.theregister.com/



"sophisticated"

wolfetone

Well I feel sorry for them if it was a sophisticated attack. There's nothing they could've done to...

Oh, it was a Magecart attack you say? On Magento you say? The same sort of attack we've known about for years and that there are patches and various protections available to prevent such a sophisticated occurring in the first place?

Colour me cynical, but there is nothing sophisticated about someone exploiting a known bug that you couldn't be bothered to fix in production. That's not a sophisticated attack, that's a bread and butter robbery which was enabled by your own inability to do your f**king job.

Re: "sophisticated"

SW10

Easy for you to suggest they were asleep on the job, but these fixes take time to bed in

Re: "sophisticated"

tip pc

from the article

The spokesperson said they could confirm that the "platform was kept up to date with all relevant security fixes."

from wolfetone

Oh, it was a Magecart attack you say? On Magento you say? The same sort of attack we've known about for years and that there are patches and various protections available to prevent such a sophisticated occurring in the first place?

do you have proof their system was not fully patched?

Re: "sophisticated"

wolfetone

I've about as much proof about what I said as they're willing to give to back up their own claim.

Security is more than just a bug fix here and there. It's the implementation, the structure, and the continual vetting of all of the relevant packages they add to their site. Like another commentator has pointed out, issues that allow this attack don't exist in a silo with Magento. It can be attacked in various ways.

They can have all the fixes they want, but if it's not implemented right, then it might as well not be patched.

Cynical Pie

and... 3... 2...1...

'We at Emma take our data protections responsibilities very seriously....'

Sounds like some people will be losing sleep over this..

cyberdemon

And I doubt an expensive mattress is going to help

johnfbw

If anyone has used their website they wouldn't be surprised it looks like it was put together by the work experience boy.

As I lay me down to sleep

Winkypop

I hope my data is mine to keep

Re: As I lay me down to sleep

Neil Barnes

Not if you're asleep on the job.

Well, if you will include third party JS at random

andy 103

The article lacks the relevant details but from memory the way it worked in the case of British Airways (https://www.theregister.com/2018/09/06/british_airways_hacked/) is that they included a shitton of third party JavaScript - hosted outside of their domain. If you don't understand why this is a bad idea, please don't become a web developer.

That JavaScript was modified so it requested other .js files (which the attackers had written themselves) from a domain which on the face of things looked legit to an average user, not that they'd see the requests their browser was making in the background anyway.

The malicious script then targets form inputs (e.g. credit card name / number inputs) and makes an ajax POST request with the form data to a third party server for storage and thereafter "shenanigans".

So, if I'm understanding correctly, years later nobody has learnt the extremely simple premise of not including random JS from third parties on your site. Yes I know there are some exceptions where you can't do this, but I'd be willing to bet it was Bob's Shitty Analytics dot BIZ or something where they wanted it for "marketing purposes".

Some smart arse will say yes but what if they modify the JS on your site directly. If they can do that my dear then you have much bigger problems. Frankly though, including third party JS pretty much amounts to exactly this! You're giving somebody else control over what can be executed on your site.

Re: Well, if you will include third party JS at random

Mike 137

" a malicious piece of code that was added to checkout pages which would skim card data from within a user's browser "

There's a lot to be said for doing all sensitive processing server side - then you wouldn't need any client side scripts at all. Consequently, you could automate content scanning to dynamically detect the presence of any (inevitably malicious) scripts before the page were served.

The apparently now standard approach of serving client side 'apps' rather than static content for everything is a certain recipe for data breaches, and is mostly entirely unnecessary.

Peter Galbavy

They are also very much into sharp practices themselves; A friend ordered one of thier products which was not delivered "next day" as promised, but weeks later. In the meantime the credit company they farm this stuff out to - if you choose that way to pay - refused to acknowledge the late delivery and the rejection of the goods and threatened (in very bad faith) a bad credit rating if she didn't pay the due installments. Since then the unopend product was eventually picked up but Emma washed their hands of the credit issues and now the whole thing is detined for the Ombudsman as Emma blames the credit company, credit company blames Emma and meanwhile my friend is both out of pocket and has "bad creditor" ticked for refusing to pay further installments for a product never accepted.

Yes, GDPR and other legislation is *supposed* to help here, but it hasn't yet.

Simple advice: avoid this lot like the plague that they are.

spireite

Well, someone somewhere with this data will be linen their pockets.

Obviously, the police will be opening a pillowcase. Once they've solved it and arrested the suspects, I have no doubt they'll be saying to them on arrest "Bedspread em", and load them into Divan.

"no evidence" personal or payment data has been abused in the wild, the company said to customers

Howard Sway

Please can we stop accepting this sorry little pseudo-excuse after breaches. Of course you have "no evidence" because you don't have access to every credit card transaction on every card in the world so you wouldn't be able to know if had happened, even if you had somehow tried to find out. What do you think stolen card details are going to be used for?

I used to be an agnostic, but now I'm not so sure.