Hackers Compromised Over 7,500 Magento Sites to Steal Data
Key Takeaways Over 7,500 Magento e-commerce websites have been compromised in a widespread cyberattack campaign since late February 2026. Attackers exploited an unauthenticated file upload...
Key Takeaways
- Over 7,500 Magento e-commerce websites have been compromised in a widespread cyberattack campaign since late February 2026.
- Attackers exploited an unauthenticated file upload vulnerability, allowing them to plant malicious files directly onto web servers.
- The campaign has impacted over 15,000 hostnames, including major commercial brands, government agencies, universities, and non-profits globally.
- The vulnerability affects various Magento environments, including Open Source, Enterprise, Adobe Commerce, and Adobe Commerce with the B2B module, even on the latest beta versions.
- Immediate action is required for Magento administrators to review file upload endpoints and apply security updates.
Widespread Magento Compromises Impact 7,500+ Sites Globally
A significant cyberattack campaign has infiltrated more than 7,500 e-commerce websites powered by Magento since late February 2026. Threat actors leveraged a critical vulnerability to upload hidden malicious files into public web directories across thousands of affected domains.
Table Of Content
This extensive campaign has spread to over 15,000 distinct hostnames, impacting a diverse range of entities from prominent commercial brands to government bodies, academic institutions, and non-profit organizations across numerous countries. Security researchers characterize this as one of the most far-reaching Magento-focused operations observed in recent years.
As a leading global e-commerce platform, Magento powers a vast ecosystem of online storefronts, from small businesses to large enterprises. Its pervasive adoption makes it an attractive target for threat actors seeking to compromise a large number of sites efficiently. When a reliable exploitation method emerges, attackers can rapidly scale their operations, as demonstrated by the thousands of unique domains falling victim within weeks of this campaign’s inception.
Campaign Uncovered by Netcraft
Netcraft researchers first detected activity associated with this campaign on February 27, 2026, and have been continuously monitoring its expansion. Among the notable organizations affected are globally recognized names such as Toyota, Fiat, Citroën, Asus, Diesel, Fila, Bandai, FedEx, BenQ, Yamaha, and Lindt.
While many compromises affected subdomains, staging environments, or regional storefronts rather than core production systems, some live customer-facing websites experienced brief disruptions before remediation efforts were implemented.
The campaign’s impact extends beyond the commercial sector. Researchers also documented defacements on regional government service domains, university websites in Latin America and Qatar, infrastructure belonging to international non-profits, and several domains linked to the Trump Organization, including trumpstore.com, trumphotels.com, and booktrump.com.
Despite the high profile of some victims, evidence suggests these sites were not specifically targeted. Instead, they appear to have been caught in an indiscriminate sweep targeting vulnerable Magento infrastructure wherever it could be found.
Most defaced pages featured simple text files displaying the attacker aliases — L4663R666H05T, Simsimi, Brokenpipe, and Typical Idiot Security — along with “greetz” messages. This practice is common within the defacement community, where attackers publicly acknowledge collaborators.
A smaller subset of defacements, observed exclusively on March 7, 2026, incorporated geopolitical messaging. Analysts concluded that this brief appearance of political content was likely an isolated incident and not indicative of the campaign’s primary objective or usual pattern of activity.
How Attackers Gained Entry: The Unauthenticated File Upload Flaw
The core of this attack appears to be an unauthenticated file upload vulnerability impacting certain Magento environments. This type of flaw is highly dangerous because it permits an attacker to write files directly onto a web server without requiring any legitimate account credentials. This means no login, no password—just a direct path to depositing files into server directories where the vulnerability allows.
Netcraft researchers validated this exploit by successfully uploading a .txt file to a test Magento instance running Magento Community 2.4.9-beta1, which was the latest available version at the time of their publication. This finding underscores that even recently updated Magento installations might remain vulnerable under specific server configurations. The scope of affected platforms includes Magento Open Source, Magento Enterprise, Adobe Commerce, and Adobe Commerce with the B2B module.
While Adobe issued a security bulletin addressing multiple Adobe Commerce vulnerabilities around the same timeframe, the specific exploit observed in this campaign does not seem to align directly with those published fixes. Analysts also noted a resemblance between this campaign and the SessionReaper Magento vulnerability from October 2025, which similarly involved unauthorized file access.
Many of the compromised pages were self-reported to Zone-H, a public defacement archive, by the notifier handle “Typical Idiot Security.” This is the same alias embedded within the defacement content itself, suggesting the actor is deliberately documenting their activities to gain recognition within the defacement community.
What You Should Do
- Immediately review all exposed file upload endpoints on your Magento-based infrastructure.
- Apply all available Adobe Commerce security updates without delay.
- Actively monitor web directories for any unauthorized file additions or modifications.
- Thoroughly investigate any unexpected files found in publicly accessible server paths.
- Implement robust intrusion detection systems (IDS) and web application firewalls (WAFs) to help detect and block malicious file uploads.
- Regularly back up your Magento sites and databases to ensure rapid recovery in case of compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.