/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers find that hackers have breached Volusion, a Shopify rival, delivering malicious JavaScript code to between 6,500 and 20,000 online stores

up to 6.5k stores impacted (including Sesame Street online store) —hackers altered a JS file hosted on the company's Google Cloud account https://www.zdnet.com/... https://twitter.com/...

ZDNet Catalin Cimpanu

Context & Ripple Effects

This breach is the sharpest early example of a pattern the related coverage keeps confirming: attackers going after e-commerce platforms themselves rather than individual stores. By editing a single JavaScript file on Volusion's own Google Cloud account, the hackers turned the platform's shared infrastructure into the delivery mechanism for skimmer code across thousands of shops, including high-profile merchants like Sesame Street's online store.

The follow-on record makes clear this was not a one-off: [[a:955511|the Keeper group has been linked to breaches of at least 570 e-commerce portals, 85% running Magento]], and [[a:957904|almost two thousand Magento 1 stores were hacked in a single weekend, likely via a zero-day that had been for sale for $5K]]. Volusion sits in the same threat class — smaller than Shopify, but hosting exactly the kind of payment-flow JavaScript attackers want.

First-order effects

  • Between 6,500 and 20,000 Volusion merchants — Sesame Street's store among them — were unknowingly serving attacker-controlled JavaScript to their shoppers, exposing checkout pages to card-skimming until the file was cleaned up.
  • Volusion faces immediate remediation and trust costs: the compromise came from its own hosted infrastructure, not any single merchant's site, so every customer inherits the incident.

Second-order effects

  • Merchants evaluating hosted platforms now weigh infrastructure security alongside price, putting pressure on Volusion to prove containment while rivals like Shopify can point to their scale — though Shopify's own later incident, in which two rogue support members stole data from over 100 merchants, shows insider risk cuts across platforms.
  • The economics of e-commerce crime shift toward platform-level attacks: one compromise of shared code or a zero-day yields thousands of storefronts at once, as the Magento 1 weekend hack demonstrated.

Third-order effects

  • If the pattern holds — Volusion, Magento, Keeper's multi-year campaign — hosted e-commerce consolidates around a security question: platforms that centralize checkout code become high-value supply-chain targets, and merchants may pay a premium for vendors who can show isolation, auditing, and fast response.
  • Regulators and payment networks face growing pressure to treat platform-side JavaScript injection as a systemic risk to card data, not a per-merchant breach, which would push liability up the stack from individual stores to the hosting platforms.

The trend: Hosted e-commerce platforms are becoming the preferred supply-chain target for financially motivated hackers, since one infrastructure compromise can skim thousands of storefronts at once.

Discussion

  • @malwrhunterteam @malwrhunterteam on x
    Nothing interesting, only probably ~6,5k @Volusion powered webshops having credit card skimmers for at least close to 2 weeks (article shows a date closer to a month), while both Volusion & Google (this no surprise, more like expected) aren't caring about it... 😂 Great find! http…
  • @campuscodi Catalin Cimpanu on x
    Hackers breach Volusion, a cloud-based provider of online stores, to collect card details from thousands of site —up to 6.5k stores impacted (including Sesame Street online store) —hackers altered a JS file hosted on the company's Google Cloud account https://www.zdnet.com/... ht…