Four affiliated online sports gear sites have disclosed a cyberattack where threat actors stole credit cards for 1,813,224 customers.

The affected websites are the following:

The sites first learned of the breach on October 15th, and after an investigation, confirmed on November 29th the customers that had their payment information stolen.

The details that have been compromised as a result of this incident are the following:

Buy Me A Coffee
  • Full name
  • Financial account number
  • Credit card number (with CVV)
  • Debit card number (with CVV)
  • Website account password

After the conclusion of the investigation, the websites sent notices to the affected individuals on December 16th, 2021.

None of the published notices to impacted customers provide any details on the nature of the incident, so the actual means of obtaining the data remains unknown.

However, as the description states, “External system breach (hacking),” this appears close to be a database breach rather than the implantation of card skimmers on the websites, although both scenarios are likely.

Whatever the case is, if you have purchased anything from these four websites, you should treat incoming communications with vigilance, monitor your bank account and credit card statements, and report any suspicious transactions immediately.

“Upon becoming aware of the incident, Tackle Warehouse took the measures referenced above. We also reported the incident to the payment card brands in an attempt to prevent fraudulent activity on the affected accounts,” reads Tackle’s notification letter to customers.

READ
Researchers Discover Espionage Campaign Targeting Indian Users via Fake Messaging Apps

“We also reported the incident to law enforcement and have worked closely with the digital forensics firm to enhance the security of our sites to facilitate safe and secure transactions.”

(Via Bleepingcomputer)