Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

Author:
Category Cyber Security

 

X-Cart

 

E-commerce software vendor X-Cart suffered a ransomware attack at the end of October that brought down customer stores hosted on the company's hosting platform.

The incident is believed to have taken place after attackers exploited a vulnerability in a third-party software to gain access to X-Cart's store hosting systems.

"We have identified what we believed to have been the vulnerability but do not wish to disclose the name until its confirmed by our security firm," Jeff Cohen, VP of Marketing for Seller Labs, the company behind X-Cart, told ZDNet in an email.

Cohen said the attackers gained access to a small number of servers, which they encrypted, effectively bringing down X-Cart stores running on top of the impacted systems. Some stores went down completely, while others reported issues with sending email alerts.

"The outage impacted a small percentage of our infrastructure, mainly those on our shared hosting servers.

"Our core systems were not impacted," Cohen said.

In the meantime, Cohen said that "all customer websites have since been restored."

Nevertheless, the outage, which lasted for a few days, rubbed some store owners the wrong way, with a few trying to organize a class-action lawsuit against the store hoster.

Class-action looming?

In response to this initiative, Cohen said the company's "first priority" during the ransomware attack "has been to get every customer back online and ensure we have a stable and secure system."

The Seller Labs exec said they are keeping communication channels open with any customer affected by the recent ransomware attack and encouraged them to reach out for help or discussions.

Asked if Seller Labs paid the ransomware gang to recover its files, Cohen said they chose to restore from backups, and that payment couldn't be made either way because "the hackers didn't provide any way to communicate."

X-Cart's free/downloadable e-commerce CMS isn't believed to have been impacted or tainted following the X-Cart ransomware incident.

X-Cart joins a long list of ransomware incidents that have impacted web hosting and data center providers. The list also includes EquinixCyrusOneCognizantA2 HostingSmarterASP.NETDataresolution.net, and Internet Nayana.

PortSwigger's The Daily Swig first reported on the X-Cart ransomware incident. ZDNet reported independently from a different source.

[ad_2]

Source link

Is your business effected by Cyber Crime?

If a cyber crime or cyber attack happens to you, you need to respond quickly. Cyber crime in its several formats such as online identity theft, financial fraud, stalking, bullying, hacking, e-mail fraud, email spoofing, invoice fraud, email scams, banking scam, CEO fraud. Cyber fraud can lead to major disruption and financial disasters. Contact Digitpol's hotlines or respond to us online.

Digitpol is available 24/7.

Email: info@digitpol.com
Europe +31558448040
UK +44 20 8089 9944
ASIA +85239733884

You must be logged in to post a comment.