ZAGG Inc., a prominent mobile accessories manufacturer, has notified customers about a significant data breach affecting credit card transactions between October 26 and November 7, 2024. The breach occurred through a third-party payment processing application called FreshClick, which was integrated into their e-commerce platform powered by BigCommerce.
According to the company's official communication, an "unknown actor" successfully injected malicious code into the FreshClick app designed to scrape credit card information during the checkout process on ZAGG.com. This sophisticated cyber attack potentially exposed customers' sensitive financial data, including names, addresses, and payment card details.
BigCommerce, the e-commerce platform provider, confirmed that their core systems were not compromised. They immediately took action by uninstalling the FreshClicks App from their customers' stores, effectively removing the malicious APIs and code that enabled the data theft.
The breach was first discovered on November 8, 2024, when BigCommerce's internal security tools detected the unauthorized intrusion. ZAGG promptly initiated an investigation and implemented a comprehensive response strategy to mitigate potential damages to their customers.
As part of their remediation efforts, ZAGG has arranged for affected individuals to receive complimentary identity protection services. Specifically, customers will be provided with 12 months of free credit monitoring through Experian IdentityWorks. The company has also notified federal law enforcement and regulatory authorities about the incident.
Customers impacted by this data breach are advised to take several protective measures. These include closely monitoring their financial account activities, placing fraud alerts with credit bureaus, and considering a credit freeze to prevent potential unauthorized credit applications.
While ZAGG has not yet disclosed the total number of customers affected by the breach, they have been transparent about the incident and are committed to supporting customers through this challenging situation. The company emphasized the importance of customer data protection and has pledged to enhance its security protocols to prevent similar incidents in the future.
BigCommerce has stressed that the compromise originated from a third-party application in their marketplace and not from a vulnerability within their platform. They continue to work closely with app developers to ensure the security of their ecosystem.
Customers with questions or concerns about the data breach can contact ZAGG's dedicated support channels or reach out to Experian for additional guidance on protecting their personal and financial information.
Found this article interesting? Keep visit thesecmaster.com, and our social media page on Facebook, LinkedIn, Twitter, Telegram, Tumblr, Medium, and Instagram and subscribe to receive tips like this.
You may also like these articles: Here are the 5 most contextually relevant blog posts:
North Korean Hackers Steal $50 Million from Radiant Capital DeFi Platform
ConnectOnCall Data Breach Exposes Personal Information of 914000 Patients
Anna Jaques Hospital Data Breach Exposes Information of Over 316,000 Individuals
Bitcoin ATM Operator Byte Federal Exposes 58,000 Users in GitLab Hack
Hackers Steal 390000 WordPress Credentials Through Malicious GitHub Repos
Anthony Denis a Security News Reporter with a Bachelor's in Business Computer Application. Drawing from a decade of digital media marketing experience and two years of freelance writing, he brings technical expertise to cybersecurity journalism. His background in IT, content creation, and social media management enables him to deliver complex security topics with clarity and insight.
“Knowledge Arsenal: Empowering Your Security Journey through Continuous Learning”
"Cybersecurity All-in-One For Dummies" offers a comprehensive guide to securing personal and business digital assets from cyber threats, with actionable insights from industry experts.
BurpGPT is a cutting-edge Burp Suite extension that harnesses the power of OpenAI's language models to revolutionize web application security testing. With customizable prompts and advanced AI capabilities, BurpGPT enables security professionals to uncover bespoke vulnerabilities, streamline assessments, and stay ahead of evolving threats.
PentestGPT, developed by Gelei Deng and team, revolutionizes penetration testing by harnessing AI power. Leveraging OpenAI's GPT-4, it automates and streamlines the process, making it efficient and accessible. With advanced features and interactive guidance, PentestGPT empowers testers to identify vulnerabilities effectively, representing a significant leap in cybersecurity.
Tenable BurpGPT is a powerful Burp Suite extension that leverages OpenAI's advanced language models to analyze HTTP traffic and identify potential security risks. By automating vulnerability detection and providing AI-generated insights, BurpGPT dramatically reduces manual testing efforts for security researchers, developers, and pentesters.
Microsoft Security Copilot is a revolutionary AI-powered security solution that empowers cybersecurity professionals to identify and address potential breaches effectively. By harnessing advanced technologies like OpenAI's GPT-4 and Microsoft's extensive threat intelligence, Security Copilot streamlines threat detection and response, enabling defenders to operate at machine speed and scale.