The Green Bay Packers recently disclosed a security breach affecting their official online retail store, packersproshop.com. The incident, discovered on October 23, 2024, involved a malicious card skimming script that potentially compromised customers’ personal and payment information.
The attack occurred between September 23-24 and October 3-23, 2024. Upon discovery, the team immediately suspended all checkout and payment capabilities on the website. The breach specifically targeted customers who made purchases using credit cards, while transactions made through PayPal, Amazon Pay, gift cards, or Pro Shop website accounts remained secure.
Compromised information includes:
– Customer names
– Billing and shipping addresses
– Email addresses
– Credit card details (numbers, expiration dates, verification codes)
Dutch security firm Sansec, which identified the breach, revealed that attackers exploited JSONP callback and YouTube’s oEmbed feature to bypass security measures. The malicious script, operating from js-stats.com, captured data from various input fields on the site.
In response, the Packers have:
– Removed the malicious code
– Enhanced security measures
– Offered affected customers three years of free credit monitoring and identity theft restoration services through Experian
Customers are advised to monitor their accounts for suspicious activity and report any fraudulent transactions to their banks and relevant authorities, including state attorneys general and the Federal Trade Commission.
