Breaking
February 4, 2025

Casio’s online store hit by bogus credit card stealing checkout form benedict.collins@futurenet.com (Benedict Collins) | usagoldmines.com


  • The UK Casio store had malicious scripts installed
  • The scripts stole credit card and customer information
  • A fake checkout form was used to steal information

An unknown threat actor installed malicious credit card skimming code into Casio UK’s ecommerce store which reportedly went unnoticed for ten days.

The company has warned customers who made purchases through the casio.co.uk domain between January 14 and 24 may have had their credit card information and customer details stolen.

The attack was discovered by Jscrambler, which notified Casio on January 28 and the malicious code was removed within 24 hours. Jscrambler says that the skimming campaign also targeted 17 other websites.

Get Incogni at 55% off with code TECHRADAR
Remove your personal information from the internet with ease. Incogni protects your online
identity and reduces unwanted robocalls and spam emails.View Deal

Magento vulnerabilities

The skimmer likely made its way on to the site via vulnerable components in the Magento webstores, Jscrambler says, and did not use any obfuscation to hide the initial malicious code.

The first skimming script could be found directly from the homepage, and would load a second-state skimmer from a server with a Russian IP address.

Where this skimmer differs from typical attacks is in its execution. Rather than harvesting credit card information from the site’s legitimate checkout screen, this campaign loaded a fake checkout form that collected the customers billing address, email address, phone number, credit card holder’s name, credit card number, credit card expiration date, and credit card CVV code.

Details such as these are frequently used in credit fraud and identity theft attacks.

Once this information is entered and the fake ‘Pay Now’ button is clicked, an error is presented to the customer asking them to verify their billing information before redirecting the customer to the legitimate Casio checkout page to continue their purchase.

However, if a customer clicked the ‘buy now’ button rather than ‘add to basket’, the script would not trigger, indicating that the attackers didn’t take much time to refine the skimming flow to also target this payment trigger.

The secondary payload did attempt to obfuscate itself using an encoding technique that has been observed since 2022 that varies parts of its code between the different sites it targets. It also used an XOR-based string concealing technique.

Jscrambler recommends if sites are going to implement Content Security Policy (CSP) protections, they do so to the best of their ability and properly build and maintain the relevant tooling to ensure the CSP works. Alternatively, sites can use automated script security software.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Millions of cheap EVs in China will get advanced self-driving features this year – leaving the rest ...

Cloudflare's new tool wants to help you spot doctored images online | usagoldmines.com

Minecraft gets new cow variants, bush types, and ambient sounds to desert biomes in the latest publi...

Google Gemini update makes the AI much more useful when your phone is locked hamish.hector@futurenet...

The Fantastic Four: First Steps trailer has lift off as Marvel finally reveals the MCU movie's uniqu...

Man indicted for two alleged DeFI hacks that stole $65 million Dan Goodin | usagoldmines.com

Best streaming devices of 2025: Amazon Fire TV, Apple TV, Roku, or Google TV? | usagoldmines.com

Acer Swift 16 AI review: A big, beautiful OLED laptop | usagoldmines.com

Beyond Copilot: 13 helpful AI tools for PC users | usagoldmines.com

Microsoft quietly removed its instructions for installing Windows 11 on an unsupported PC – is this ...

Could AI be the key to solving our productivity woes? A personal assistant could solve many issues ...

Nintendo Switch 2 has some big shoes to fill as the original Switch officially surpasses 150 million...

The next ID@Xbox showcase is scheduled to take place later this month | usagoldmines.com

Samsung patents Galaxy Ring gesture feature that will let you control your tablet or laptop like Ton...

Google Messages will get a big emergency texting upgrade soon –here's what's coming | usagoldmines....

How emotionally intelligent AI cranks up CX potential | usagoldmines.com

Google Sheets is getting faster and more effective, and I can't wait to ditch Excel for good | usag...

Former PlayStation boss is hoping for ‘something that is still hidden to us’ to be revealed in the N...

Marvel's Spider-Man 2's second hotfix fixes crashing issues and addresses a frame rate-related bug ...

Sick of your MacBook starting when you open the lid? Apple has just revealed a fix alexblake.techrad...

Google Maps could get its most useful Gemini AI upgrade so far soon to speed up your searches | usa...

Everything new on Prime Video in February 2025 grace.morris@futurenet.com (Grace Morris) | usagoldmi...

Google Pixel Watches may be about to get a battery-extending charging feature - and it's one Pixel o...

The Ninja Double Stack is the best air fryer in the world – and it just got a 2025 revamp that makes...

OpenAI's Deep Research smashes records for the world's hardest AI exam, with ChatGPT o3-mini and Dee...

Opera Air Brings Meditation and Wellness to Web Browsing Tim Hardwick | usagoldmines.com

WhatsApp to Soon Let You Schedule Events in Private Chats Tim Hardwick | usagoldmines.com

Salesforce is slashing 1,000 jobs, but says workers will be able to reapply | usagoldmines.com

Sonos may have finally fixed its app’s biggest remaining problem | usagoldmines.com

A web browser that relieves stress? Sounds crazy. Then I tried Opera Air | usagoldmines.com

I tested OpenAI's o1 model in Microsoft Copilot and it's a little overwhelming erichs211@gmail.com (...

What if you replaced your TikTok addiction with something useful? | usagoldmines.com

Stuck in the app trap? Why more software isn’t the answer to business growth | usagoldmines.com

Turns out Dyson's new handheld vacuum is just a V8 without its wand, and I feel cheated | usagoldmi...

'Somewhat robot, somewhat human': designer used 12,000ft fiber optic cable to weave a striking 50lb ...

Apple Music's awesome $2.99 deal is your reason to finally switch from Spotify jacob.krol@futurenet....

Microsoft Paint brushes up on AI erichs211@gmail.com (Eric Hal Schwartz) | usagoldmines.com

Popular Linux orgs Freedesktop and Alpine Linux are scrambling for new web hosting Kevin Purdy | usa...

Microsoft 365 Is Raising Prices and Ditching Its Free VPN Michelle Ehrhardt | usagoldmines.com

The Beatles' 'Now and Then' Was Made With AI (and That's Okay) Jake Peterson | usagoldmines.com

As Apple Vision Pro Turns One, Here's What's Next Juli Clover | usagoldmines.com

Bonobos recognize when humans are ignorant, try to help John Timmer | usagoldmines.com

Concern about SpaceX influence at NASA grows with new appointee Eric Berger | usagoldmines.com

Sick of your gaming laptop’s awful battery life? Here’s how to extend it | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Swifdoo PDF for Windows review: Essential features and easy to use | usagoldmines.com

uBlock Origin is dead for Chrome, but ad blockers live on | usagoldmines.com

Microsoft is killing its VPN soon. Here’s what you should do | usagoldmines.com

New RTX 5090s could take ‘3 to 16 weeks’ to arrive | usagoldmines.com

Microsoft silently erases tip for installing Windows 11 on older PCs | usagoldmines.com

Microsoft Paint gets Copilot button for generative AI features | usagoldmines.com

Why your fraying USB cables are a problem | usagoldmines.com

This ultra-portable mouse, the size of a car remote, still has 6 buttons | usagoldmines.com

Our favorite high-speed portable SSD just hit its best price: $40 | usagoldmines.com

Want better Google search results? Start swearing | usagoldmines.com

Best Windows backup software 2025: Protect your data! | usagoldmines.com

Microsoft’s latest AI feature may just stop working. Here’s why | usagoldmines.com

This superb Ryzen 7 mini PC with 24GB RAM is $479 today | usagoldmines.com

This budget Asus laptop with 16GB RAM is even cheaper now at $380 | usagoldmines.com

Samsung’s 34-inch 1440p ultrawide gaming monitor is $199 off | usagoldmines.com

Microsoft tests new PowerToys app that can pull audio from video files | usagoldmines.com

The Sims and The Sims 2 now available digitally for the first time | usagoldmines.com

Help your family browse safely with this VPN | usagoldmines.com

Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how t...

“Zero warnings”: Longtime YouTuber rails against unexplained channel removal Ashley Belanger | usago...

Anthropic dares you to jailbreak its new AI model Kyle Orland | usagoldmines.com

OpenAI's ‘Deep Research’ Can Actually Make Professional Reports With Citations Khamosh Pathak | usag...

The DJI Osmo Action 5 Pro Is Like a GoPro for Power Users Michelle Ehrhardt | usagoldmines.com

Nine of the Best Valentine’s Day Dates That Aren’t Eating at a Restaurant Allie Chanthorn Reinmann |...

How I Removed Stubborn Water Stains From My Wall Lindsey Ellefson | usagoldmines.com

Apple Says It Doesn't Approve of EU Porn App Juli Clover | usagoldmines.com

Google Search Adds the Handiest Little Shortcut to Its Widget Kellen | usagoldmines.com

Apple Stops Signing iOS 18.2.1, Preventing Downgrading Juli Clover | usagoldmines.com

Judge Again Denies Apple's Attempt to Intervene in Google Search Engine Lawsuit Juli Clover | usagol...

DeepSeek R1 is now available on Nvidia, AWS, and Github as available models on Hugging Face shoot pa...

Tariffs may soon spike cost of cars, household goods, consumer tech Ashley Belanger | usagoldmines.c...

Let us spray: River dolphins launch pee streams into air Jennifer Ouellette | usagoldmines.com

Your Galaxy S25 First Impressions? Mine Aren’t Great. Kellen | usagoldmines.com

First Galaxy S25 Update Could Drop at Any Moment Kellen | usagoldmines.com

The Out-of-Touch Adults' Guide to Kid Culture: Is Beating Up a Robot Wrong? Stephen Johnson | usagol...

You Can Save a Lot of Money by Growing Your Own Seedlings Instead of Buying Plants Amanda Blum | usa...

You Can Use an Uncensored Version of DeepSeek Through Perplexity David Nield | usagoldmines.com

Why You Should Buy Your Valentine's Day Flowers Early Meredith Dietz | usagoldmines.com

The Boox Note Air 4C Is a Color E-Reader and Digital Notebook in One Joel Cunningham | usagoldmines....

My Seven Favorite Apps for Getting Free Stuff Lindsey Ellefson | usagoldmines.com

Apple Music Has an Amazing Deal for New Users Right Now Jake Peterson | usagoldmines.com

These Samsung Galaxy Buds 3 Are Under $80 Right Now Pradershika Sharma | usagoldmines.com

EU's AltStore Gets Apple-Approved Pornography App Juli Clover | usagoldmines.com

NYT Strands hints and answers for Tuesday, February 4 (game #338) | usagoldmines.com

NYT Connections hints and answers for Tuesday, February 4 (game #604) | usagoldmines.com

Quordle hints and answers for Tuesday, February 4 (game #1107) | usagoldmines.com

I’ve loved WWE for 25 years, and there’s no better time to start watching thanks to Netflix john-ant...

Help! We're drowning in email spam, it's about to get worse and there's nothing we can do to stop it...

You Can Save a Lot of Money by Growing Your Own Seedlings Instead of Buying Plants Amanda Blum | usa...

Apple's WWDC 2025 Swift Student Challenge Now Live Juli Clover | usagoldmines.com

Apple Relaunched the HomePod Two Years Ago Today Hartley Charlton | usagoldmines.com

Apple Releases New Version of iOS 18.3 for iPhone 11 Juli Clover | usagoldmines.com

Nvidia's new Smooth Motion technology is exclusive to RTX 5000 series GPUs, but not for long - RTX 4...

Infants, to teens, to college graduates, and now AI finally enters the workforce - as Agents | usag...

Patient monitors may have some worrying security flaws | usagoldmines.com

Leave a Reply