Hackers Steal Credit Card Data from Thousands of DiscountMugs Customers
A massive Magecart card skimming attack on DiscountMugs.com exposes the financial and personal information of thousands of holiday shoppers. Company executives remain silent as the breach adds to a growing list of e-commerce security failures.
DiscountMugs.com suffers a major data breach after hackers inject malicious card skimming code into the online retailer's payments page. The attack, which occurs over a four-month period leading up to the 2018 Christmas holiday season, exposes highly sensitive customer information. Malicious actors successfully siphon credit card numbers, security codes, expiration dates, names, addresses, phone numbers, and email addresses.
Security researchers attribute this cyberattack to the notorious Magecart group, a collective of hackers known for scraping payment data directly from e-commerce checkout pages. This incident places DiscountMugs alongside other major companies like British Airways, Newegg, and Ticketmaster that experience similar web-skimming attacks. Although the exact victim count remains unconfirmed, the site's high traffic rank in the top 10,000 U.S. websites suggests thousands of shoppers face significant identity theft risks.
Parent company Bel USA and its private equity investor Comvest refuse to respond to media inquiries regarding the security lapse. The company removes the malicious code upon discovery but fails to provide public details about the scope of the incident or how the hackers initially compromised the site. This silence leaves affected customers in the dark about the safety of their financial profiles.