Network Solutions: 573,928 possibly compromised in attack
Network Solutions issued a Data Security Alert (DSA) on Friday, which reported the discovery of malicious code planted on servers supporting their E-Commerce merchants' websites. The code, discovered on 4,343 Network Solutions customer sites …
Context & Ripple Effects
For Network Solutions, this disclosure lands on top of two years of accumulated trust damage: a 2007 web-host breach that exposed passwords for 6,000 clients, followed by the January 2008 domain front-running controversy, in which the registrar was widely accused of holding names customers searched for and defended itself publicly against the charge. The company's Data Security Alert now extends the problem from reputation to payment data.
The scope is what makes it notable rather than routine: malicious code planted on servers backing the e-commerce offering touched 4,343 customer sites at once, with 573,928 records possibly compromised — a single hosting-layer compromise scaled across an entire merchant base.
First-order effects
- Merchants on Network Solutions' e-commerce platform must assume their checkout pages were instrumented, putting roughly 573,928 customer records into dispute-resolution and issuer-notification workflows they did not choose.
- Network Solutions faces direct PCI-compliance and contractual exposure across its hosted-commerce business, on top of a customer base already primed to leave by the 2008 front-running episode.
Second-order effects
- Small merchants who chose managed hosting precisely to avoid running their own secure checkout now bear fraud losses and re-issuance costs anyway, sharpening the question of whether shared e-commerce hosting transfers risk or concentrates it.
- Competing hosts and registrars gain a sales wedge: security isolation guarantees for storefronts, pitched against a rival whose second major hosting-side security event since 2007 is public record.
Third-order effects
- If attackers keep favoring the hosting layer over individual store defenses, liability for card-data breaches migrates up the stack toward platform operators, making compliance audits and breach-notification duties a structural cost of running multi-tenant commerce infrastructure.
- Payment-card fraud increasingly routes through injected code on legitimate merchant pages rather than stolen databases alone, pushing issuers and processors toward transaction-level anomaly detection instead of point-in-time attestation of the merchant.
The trend: Multi-tenant e-commerce hosting is emerging as a single point of compromise where one server intrusion converts directly into mass payment-card exposure, shifting breach risk and liability from individual stores to the platforms that host them.