Last October, the Incident Response Department of RIA (CERT-EE) identified a few hundred e-shops that were using an outdated version of the Magento platform and were therefore vulnerable to one particular security flaw. Many of them abided by the recommendation to upgrade, but there are still at least a hundred e-shops using outdated Magento software.
‘However, such e-shops are tempting targets for attackers, as they allow hackers to steal the data of the customers of the e-shop, including the data of their bank cards, or perform other malicious activities. The reality of the threat is illustrated by the fact that we have recently learned from one cyber incident with an impact that falls into this category,’ explained Tõnu Tammer, Head of CERT-EE.
Attackers use many of the vulnerabilities disclosed last year to steal the bank cards of the customers of e-shops or other people. This can be done by installing malware to the e-shop or by adding a phishing page to harvest data from potential victims.
Here are RIA’s recommendations for e-shops to protect themselves against cyber attacks:
- Update your software (including extensions) regularly.
- Make sure that the contact details for your e-shop are up to date in the register of the Estonian Internet Foundation. This way, the CERT-EE alerts will definitely reach you.
- Restrict access to the e-shop admin panel based on actual need. You can read more about that here.
- Implement two-factor authentication for the management accounts of your e-shop. You can find a tutorial on how to do this here.
- If possible, use a web application firewall (WAF).
- Regularly back up the contents of your web server and database to an external location. With a working backup, you will be able to restore your web service faster in the event of a cyber incident (e.g. the installation of malware).
- Test your websites regularly (preferably with automated tools) to make sure they do not have easily identifiable security flaws.
INFORMATION SYSTEM AUTHORITY
23 May 2023