Segway store hacked, customer details stolen

Image of people riding segways
(Image credit: Maxmann via Pixabay)

Segway, the company most famous for its two-wheeled “hoverboard”, has confirmed it suffered a cyberattack that saw it leak credit card data to malicious actors.

The company’s online store was breached sometime around January 6, 2022 (possibly even earlier), by a group known as Magecart Group 12. As the name suggests, the group works to steal credit card information by integrating the Magecart script onto vulnerable online stores. The script intercepts transaction data during the checkout in an online store, which is a process also known as form jacking, digital skimming, or e-skimming. 

Cybersecurity researchers from Malwarebytes, which first spotted the breach, said it’s likely that the malicious actors exploited a vulnerability in the Magento CMS that the store uses. Once the CMS was breached, they embedded the skimmer in the last place anyone would look - the favicon files, images that are used to display small icons, such as website logos, in the web page browser tab. 

Hiding malware in icons

This particular image, Malwarebytes further explains, pretends to display the site’s copyright. On the surface, it does just that, but beneath, it loads an external favicon that holds the malicious JavaScript.

What makes it difficult for security pros to spot this script is the fact that it won’t be seen unless the page is analyzed with a hex editor. BleepingComputer claims that this technique has been “well-documented”, and that it’s been used by “skillful” Magecart groups, for years now. 

Claire's, Tupperware, Smith & Wesson, Macy's, and British Airways, have all been compromised in the same fashion, the company says.

As for Segway, most of its users come from the US (55%) and Australia (39%). We don’t know how many customers might be affected by this incident. Segway is yet to make an announcement, as the company’s newsroom page, blog, and Twitter account, have no mention of the breach.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Casio logo
Casio’s online store hit by bogus credit card stealing checkout form
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
European Space Agency hack sees official store hijacked to steal customer details
A computer being guarded by cybersecurity.
Wacom warns users their data may have been stolen in breach
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
Zagg warns customers their data may have been stolen in third-party cyberattack
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
Google system abused by hackers to hijack ecommerce stores
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Latest in News
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI