The Liquor Control Board of Ontario (LCBO), a Canadian government enterprise and the country’s largest beverage alcohol retailer, revealed that threat actors have breached its website to inject malicious code that could steal customer and credit card information at check-out.
On Wednesday LCBO revealed that third-party forensic investigators found a credit card stealing script that was active on its website for five days.
They stated that the customers who provided personal information on their check-out pages and proceeded to the payment page on LCBO.com between January 5, 2023, and January 10, 2023, may have had their information compromised.
While the malicious script was active on the retailer’s website, the attackers could gather various personal and financial information submitted by customers during the check-out process.
The details include customers’ names, email and mailing addresses, credit card information, Aeroplan numbers, and LCBO.com account passwords.
However, LCBO added that customers who used the mobile app or the vintagesshoponline.com online store to make orders were not affected.
The investigation process is ongoing and the firm is working on identifying all customers affected by this data breach.
The government-controlled company employs more than 8,000 people and operates 680 retail stores and five regional warehouse facilities.
It’s also a wholesaler to 450 grocery stores and provides wholesale support for 18,000 bars and restaurants.
Image Credits : Forbes














Comments