A prolific hacker gang that has breached numerous companies by exploiting Adobe software has claimed another major hit in the form of car manufacturer Citroën, the Guardian has learned.
Citroën had one of its German websites hacked to include a backdoor, which is a method of bypassing normal authentication systems, and which may have allowed the attackers to make off with whatever data was sitting on site’s server.
A Citroën Germany spokesperson said law enforcement were to be contacted about the breach as it appeared to be a criminal act. Some customer data was stolen, the spokesperson said, but it is unclear how many are affected. Customers have been contacted and will be advised to check their bank accounts for any suspicious transfers.
The attackers managed to embed the backdoor on shop.citroen.de, a fan site for buying Citroën-based gifts. After disclosure by the Guardian and Alex Holden, chief information security officer at Hold Security, the backdoor was removed, but investigations into the breach continue. The backdoor file was live from at least August 2013.