Early last month, it was disclosed that Ticketmaster suffered a data breach through a third party service provider as part of a payment card hacking campaign; Ticketmaster was just one of hundreds of victims. The threat actor, Magecart, compromised over 800 e-commerce sites by secretly installing digital card-skimming software on third-party components and services used by these retailers.
This breach highlights the growing number of third party service providers that retail and e-commerce companies rely on - and this is not unique to the retail industry, as most industries rely on similar third parties across their supply chains. Sometimes these organizations can have up to tens of thousands of third parties, all with a specific business function.
Retailers face a unique challenge by relying on so many third parties — this includes e-commerce businesses and others — where even one line of code compromised within that third party can affect an extremely significant amount of retailers. As the old saying goes, it only takes one. There is a network of interdependence clearly evidenced here by the third party platforms and service providers that compromised other retailers in addition to Ticketmaster. These service providers include Inbenta, SocialPlus, PushAssist, CMS Clarity Connect, and Annex Cloud.
