Site navigation

Popularity of ‘Formjacking’ Surges, Symantec Research Shows

Ross Kelly

,

Cybercrime Vistalworks

In 2019, Symantec halted more than 3.7 million formjacking attacks on organisations around the world.

Cybercriminals are implanting code to access payment card numbers across thousands of websites online, according to research by Symantec.

The cybersecurity firm revealed that ‘formjacking’ has affected more than 4,800 websites every month, with victims including global firms such as Ticketmaster and British Airways (BA).

The formjacking attack enables cybercriminals to infect web servers and skim consumers’ payment information.

In 2019, Symantec halted more than 3.7 million formjacking attacks on organisations around the world.

Recommended: Xiaomi Scooter Security Flaw Allows Hackers to Control Acceleration

As other forms of cyber attacks such as ransomware and cryptojacking have become less lucrative, would-be attackers are increasingly turning to this form of attack method.

This rise in popularity, Symantec said, has prompted formjacking to be dubbed the “breakthrough threat of 2018.”

“This threat showed explosive growth – and potentially big profits – at the end of the year, ensuring that it’s likely to draw plenty of flies in 2019 and beyond,” the firm said in a blog post.

Often using third-party apps to infiltrate websites, Symantec said formjacking highlights growing concerns over supply chain vulnerabilities, an issue that businesses and organisations around the world must address.

Related: Emerging Attack Vectors are Putting UK Organisations at Risk

Cybercriminals require only a few basic lines of code, loaded onto a website, to access sensitive information. This easy access poses a huge threat to retailers or any company that collects personally identifiable information from customers online.

Although this latest attack method is growing in popularity, ransomware and cryptojacking still pose a significant threat to organisations globally, the firm said.

With the decline in the value of cryptocurrencies, such as Bitcoin or Ethereum, the lucrative nature of these attack methods has declined. However, researchers insisted that attacks are “easy to instigate and manage, meaning those criminals playing the long game can still make money.”

Throughout 2018, Symantec blocked four times as many cryptojacking attacks than the year previous, and so far in 2019, it remains a viable threat.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data