Researchers find that hackers have breached Volusion, a Shopify rival, delivering malicious JavaScript code to between 6,500 and 20,000 online stores
up to 6.5k stores impacted (including Sesame Street online store) —hackers altered a JS file hosted on the company's Google Cloud account https://www.zdnet.com/... https://twitter.com/...
Context & Ripple Effects
This breach is the sharpest early example of a pattern the related coverage keeps confirming: attackers going after e-commerce platforms themselves rather than individual stores. By editing a single JavaScript file on Volusion's own Google Cloud account, the hackers turned the platform's shared infrastructure into the delivery mechanism for skimmer code across thousands of shops, including high-profile merchants like Sesame Street's online store.
The follow-on record makes clear this was not a one-off: [[a:955511|the Keeper group has been linked to breaches of at least 570 e-commerce portals, 85% running Magento]], and [[a:957904|almost two thousand Magento 1 stores were hacked in a single weekend, likely via a zero-day that had been for sale for $5K]]. Volusion sits in the same threat class — smaller than Shopify, but hosting exactly the kind of payment-flow JavaScript attackers want.
First-order effects
- Between 6,500 and 20,000 Volusion merchants — Sesame Street's store among them — were unknowingly serving attacker-controlled JavaScript to their shoppers, exposing checkout pages to card-skimming until the file was cleaned up.
- Volusion faces immediate remediation and trust costs: the compromise came from its own hosted infrastructure, not any single merchant's site, so every customer inherits the incident.
Second-order effects
- Merchants evaluating hosted platforms now weigh infrastructure security alongside price, putting pressure on Volusion to prove containment while rivals like Shopify can point to their scale — though Shopify's own later incident, in which two rogue support members stole data from over 100 merchants, shows insider risk cuts across platforms.
- The economics of e-commerce crime shift toward platform-level attacks: one compromise of shared code or a zero-day yields thousands of storefronts at once, as the Magento 1 weekend hack demonstrated.
Third-order effects
- If the pattern holds — Volusion, Magento, Keeper's multi-year campaign — hosted e-commerce consolidates around a security question: platforms that centralize checkout code become high-value supply-chain targets, and merchants may pay a premium for vendors who can show isolation, auditing, and fast response.
- Regulators and payment networks face growing pressure to treat platform-side JavaScript injection as a systemic risk to card data, not a per-merchant breach, which would push liability up the stack from individual stores to the hosting platforms.
The trend: Hosted e-commerce platforms are becoming the preferred supply-chain target for financially motivated hackers, since one infrastructure compromise can skim thousands of storefronts at once.