Organizations that fail to vet third-party suppliers properly are vulnerable to a threat that steals credit card data over long periods of time, according to a July 2018 IBM X-Force advisory.

The threat alert outlines details about a recent breach against Ticketmaster that affected several of its third-party websites. According to the advisory, a threat group used a tactic called digital skimming to harvest credit card information, login credentials and names from online forums.

The group, dubbed Magecart, has been running the campaign since at least December 2016.

Digital Skimming Threat Exploits Third-Party Access

It’s important to note that Magecart launched its attack not through Ticketmaster itself, but via one of its digital suppliers, Inbenta, and possibly through a second vendor called SocialPlus.

This incident shows how an extended ecosystem of partners and suppliers can significantly expand the perimeter that security professionals must protect. A May 2018 study from Kaspersky Lab found that incidents affecting third-party infrastructure have led to an average loss of $1.47 million for large enterprises.

How Can Organizations Thwart Third-Party Threats?

While malicious actors have been secretly inserting physical devices to skim credit card data at point-of-sale (POS) terminals for years, digital skimming makes this threat much more difficult to contend with. This is especially true for large organizations that oversee dozens of websites, landing pages and other digital properties that prompt customers to enter their personal data.

To keep third-party threats in check, IBM experts recommend:

  • Taking inventory of third-party network connections to understand where they are coming from, where they are going to and who has access;
  • Conducting vulnerability assessments on their external-facing hosts and cloud environments to look for services that are listening for inbound connections; and
  • Using encryption to ensure that their sensitive data is useless to cybercriminals in the event that it is stolen via unsecured third-party access.

More from

Increasingly Sophisticated Cyberattacks Target Healthcare

4 min read - It’s rare to see 100% agreement on a survey. But Porter Research found consensus from business leaders across the provider, payer and pharmaceutical/life sciences industries. Every single person agreed that “growing hacker sophistication” is the primary driver behind the increase in ransomware attacks. In response to the findings, the American Hospital Association told Porter Research, “Not only are cyber criminals more organized than they were in the past, but they are often more skilled and sophisticated.” Although not unanimous, the…

4 min read

Ransomware Renaissance 2023: The Definitive Guide to Stay Safer

2 min read - Ransomware is experiencing a renaissance in 2023, with some cybersecurity firms reporting over 400 attacks in the month of March alone. And it shouldn’t be a surprise: the 2023 X-Force Threat Intelligence Index found backdoor deployments — malware providing remote access — as the top attacker action in 2022, and aptly predicted 2022’s backdoor failures would become 2023’s ransomware crisis. Compounding the problem is the industrialization of the cybercrime ecosystem, enabling adversaries to complete more attacks, faster. Over the last…

2 min read

Machine Learning Applications in the Cybersecurity Space

3 min read - Machine learning is one of the hottest areas in data science. This subset of artificial intelligence allows a system to learn from data and make accurate predictions, identify anomalies or make recommendations using different techniques. Machine learning techniques extract information from vast amounts of data and transform it into valuable business knowledge. While most industries use these techniques, they are especially prominent in the finance, marketing, healthcare, retail and cybersecurity sectors. Machine learning can also address new cyber threats. There…

3 min read

HHS Releases Hospital Cyber Resiliency Landscape Analysis

4 min read - On April 17, 2023, The U.S. Department of Health and Human Services (HHS) 405(d) Program announced the release of its Hospital Cyber Resiliency Initiative Landscape Analysis. This landmark analysis reports on domestic hospitals’ current state of cybersecurity preparedness. The scope of the HHS study was limited to activities that protect access to patient care and safety and reduce the negative impact of cyber threats on clinical operations. Breaches of sensitive data were considered only if the breach had a direct…

4 min read