Twenty pounds and a few hours

In September, the security firm Gambit published an unusually detailed account of a criminal campaign against online shops. It was run by one person using freely available AI tools. In under a week that month, 105 attacks were launched and at least 27 companies were compromised. Where the attackers got in, it usually took less than a day, and often just a few hours.

The person behind it typed only a few short instructions for each target. The AI tools did the rest: finding weaknesses, breaking in, and planting code on checkout pages that copied customers’ card details as they typed. More than 600,000 card records were taken from two companies alone. Gambit puts the average cost of attacking each company at about $25 in AI charges, roughly £20. (SecurityWeek’s report has the detail.)

Why these shops

The targets were picked from a website ranking service, and the attackers deliberately chose shops running their own custom-built code.

That detail should catch a board’s eye. Custom websites are everywhere: an online shop, a donation page, a booking or enrolment form, built once by an agency or a capable member of staff, launched, and then left alone. It works, and people can use it. So there is never an obvious moment to spend money on updating it, and the work gets put off until nobody remembers it was needed.

For a long time, that was a reasonable gamble for a smaller organisation. Breaking into one modest website took a skilled person days of effort, and there were richer targets elsewhere. At £20 and a few hours a time, every website is worth trying. The UK’s National Cyber Security Centre warned last year that the gap between a weakness becoming known and being exploited had already shrunk to days, and that AI would almost certainly shorten it further.

We have seen this attack before

The technique itself is old. In 2018, attackers placed similar code on British Airways’ payment page, copying customers’ card details as they booked. The Information Commissioner’s Office later fined the airline £20 million, and said it should have had monitoring in place to spot changes to its website code.

That attack needed a capable criminal team. September’s campaign shows the same kind of attack run at scale by one person, for the price of a takeaway.

Two further details deserve a board’s attention. At a wine retailer, the website was restored to a clean version, but the attacker had left behind a small scheduled job that put the card-copying code back every two minutes. At a bicycle retailer, the attacker’s tools deleted backup tables from the shop’s database. Restoring a clean copy does not prove the attacker has gone, and backups only help if they survive someone who has got in with administrator rights.

The decision nobody took

When a website goes without updates because it still works, a risk has been accepted. In most organisations, nobody with the authority to accept it was ever asked.

Boards understand this in other settings. Nobody would leave a leaking roof unrepaired because the building is still standing. Websites, online shops and payment pages need the same kind of planned maintenance, yet they are usually bought as projects that end on launch day, and the supplier’s contract often ends there too.

I wrote recently about a web agency whose access to a client’s files outlived the project by more than two years. The same pattern applies here: everyone did their part of the job, and nobody owned what happened next.

What a board can ask

None of these questions needs technical knowledge to ask, and each has a factual answer:

  • What do we run that anyone on the internet can reach, including old campaign sites and forms, and who owns each one?

  • Which of them are custom-built, and who maintains that code today?

  • When a security fix is released, how many days does it take us to apply it, and how do we know?

  • Does our supplier’s contract cover security updates after launch, and how quickly?

  • Would we know if the code on our payment or donation page changed without our say-so?

The answers may show that some risks are worth carrying. That is a legitimate decision for a board, as long as it is made on the record by someone entitled to make it. The people running campaigns like this one have already done their sums.

Next
Next

The security setting everyone thought was on