/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Report: a group known as Keeper has breached at least 570 online e-commerce portals since 2017; 85% of the victims' sites were running Magento software

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

The Keeper report lands in a well-documented arc of Magento-focused skimming: an unauthenticated exploit published in 2019 put hundreds of thousands of Magento storefronts within reach of any attacker, and the platform's long tail of self-hosted shops has been the recurring victim pool since.

Keeper is one operator in a broader criminal ecosystem — Magecart crews have moved from storefront exploits to infrastructure-level hunting like scanning unsecured AWS S3 buckets, and the same playbook hit Shopify rival Volusion, delivering malicious JavaScript to thousands of stores through a single breach.

First-order effects

  • Merchants running self-hosted Magento stores — 85% of Keeper's known victims — face immediate pressure to audit their checkout pages for injected skimmer code and patch the vulnerabilities that made the platform the dominant target.
  • Shoppers who bought from the 570+ compromised portals since 2017 have had card data exposed to a group whose operations span years, not a single incident.

Second-order effects

  • Hosted platforms gain a security selling point: every high-profile Magento breach pushes merchants toward rivals like Shopify, whose centralized model removes the patching burden that Keeper exploited — a dynamic already visible in the Volusion compromise, where one upstream breach cascaded to thousands of tenants.
  • Security vendors and card networks respond with detection tooling and stricter compliance enforcement on storefront integrity, as seen when the UK's NCSC directly warned over 4,000 stores about Magecart-driven customer-data theft.

Third-order effects

  • If the pattern holds — persistent groups like Keeper exploiting the self-hosted long tail while regulators escalate warnings — responsibility for checkout security migrates structurally from individual merchants to platforms, shrinking the viable market for unmanaged e-commerce software.
  • Skimming becomes a durable service economy rather than opportunistic hacking: specialized groups divide labor between exploit discovery, infrastructure targeting, and monetization, which raises the baseline threat every online store must price in.

The trend: Card-skimming groups are industrializing attacks against self-hosted e-commerce platforms, steadily shifting merchant trust — and regulatory attention — toward centrally managed storefronts.

Discussion

  • @gurgling_mrd AJ Durling on x
    Hackers also accidentally leaked more than 184,000 stolen cards through an improperly secured backend server. ‘Keeper’ hacking group behind hacks at 570 online stores... via @zdnet #infosec #tech #TuesdayTravel https://www.zdnet.com/...
  • @campuscodi Catalin Cimpanu on x
    NEW: ‘Keeper’ hacking group behind hacks at 570 online stores -Hackers engaged in web skimming (Magecart) -Group has been active since Apr 2017 -85% of victim stores were running Magento -One of the Keeper backends also leaked 184k card details (whoops) https://www.zdnet.com/... …