Missing MFA on Admin Accounts Led to Payment Card Skimming at Danish Fashion Brand
Hackers injected malicious JavaScript (a 'Magecart'-style attack) into Designbysi's website over a three-month period, silently stealing customer payment card data at checkout. The Danish DPA found the root cause was the absence of two-factor authentication for staff accounts with access to critical website scripts, meaning a single compromised credential was enough to introduce the malicious code. This violates GDPR Article 32(1), which requires organisations to implement appropriate technical and organisational measures commensurate with the risk — and payment data is unambiguously high-risk. The case illustrates that failing to apply basic access controls to privileged functions is not just a technical shortcoming but a legal liability under European data protection law.
Tactical Insight
Immediate actions
- Enforce multi-factor authentication (MFA) on all accounts with write or administrative access to website code, CMS, and hosting platforms.
- Conduct an emergency audit of all third-party and first-party JavaScript files loaded on checkout and payment pages to detect unauthorised modifications.
Long-term improvements
- Implement a Content Security Policy (CSP) header to restrict which scripts are permitted to execute on sensitive pages, reducing the blast radius of future injections.
- Apply the principle of least privilege to all staff accounts, ensuring only personnel who require script-editing access are granted it and that access is regularly reviewed.
- Establish a formal change-management process requiring peer review and integrity verification (e.g., subresource integrity hashes) before any script is deployed to production.
Detection measures
- Deploy file integrity monitoring or a web application firewall (WAF) with JavaScript injection detection to alert on unauthorised changes to website assets in near real-time.
- Implement continuous monitoring and logging of all administrative logins and script-modification events, with alerts for anomalous activity outside business hours.