Fitness Depot notifies customers of data breach

The fitness retailer has said its ISP was to blame for a breach of its online store

Fitness Depot notified its customers that their personal and financial information may have been stolen as part of an attack impacting the company's e-commerce platform.

The Canadian retailer was informed of the data breach on May 20, and recently sent a breach notification letter to all potentially impacted customers.

Per Fitness Depot’s letter, attackers compromised the company’s online store and gained access to customers’ personal and financial information. Information accessed by the attackers may have included customers' names, addresses, contact information and credit card numbers.

Based on the breach notification letter, all signs point to Fitness Depot having suffered from a Magecart attack. In these attacks, Magecart groups hack an e-commerce store’s checkout page and inject malicious JavaScript-based scripts that steal customer information entered into online payment forms. 

Though Fitness Depot discovered the breach on May 20, 2020, it dates as far back as Feb. 18, 2020. While customers who placed orders for home delivery were impacted between Feb. 18 and April 27, any customer who ordered products for home delivery or in-store pick-up would have been affected between April 28 and May 22.

"Once our customers where (sic) redirected to this form the customer information was copied without the authorization or knowledge of Fitness Depot," the company explained. "This is how the personal information was captured and stolen."

While Fitness Depot has stated "personal information was captured and stolen" during the breach, the company also shared it "has no knowledge that any of our customer information was compromised in any manner." Regardless, Fitness Depot has advised customers to protect themselves against identity fraud by monitoring their credit reports and reviewing account statements regularly.

Fitness Depot blames its internet service provider for the data breach, claiming it "neglected to activate the anti-virus software on our account." It’s unclear what Fitness Depot is referring to since it’s not typically an ISP’s job to equip its customers' e-commerce platforms with anti-virus software.

Featured Resources

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Simplify cluster security at scale

Centralised secrets management across hybrid, multi-cloud environments

Download now

The endpoint as a key element of your security infrastructure

Threats to endpoints in a world of remote working

Download now

2021 state of IT asset management report

The role of IT asset management for maximising technology investments

Download now

Recommended

How to protect against a DDoS attack
Security

How to protect against a DDoS attack

14 Oct 2020
What is hacktivism?
hacking

What is hacktivism?

13 Oct 2020
Microsoft: Iranian hackers are exploiting ZeroLogon flaw
Security

Microsoft: Iranian hackers are exploiting ZeroLogon flaw

6 Oct 2020
The Ritz suffers data breach after hackers pose as staff
data breaches

The Ritz suffers data breach after hackers pose as staff

17 Aug 2020

Most Popular

Microsoft CEO warns of video call fatigue
video conferencing

Microsoft CEO warns of video call fatigue

7 Oct 2020
Raspberry Pi Compute Module 4 launches with PCIe support
Hardware

Raspberry Pi Compute Module 4 launches with PCIe support

19 Oct 2020
Google blocked record-breaking 2.5Tbps DDoS attack in 2017
Security

Google blocked record-breaking 2.5Tbps DDoS attack in 2017

19 Oct 2020