Cyber Incident Victim: Lime Crime
Date:
Oct 2014
Location:
United States of America
Summary
A cosmetics company experienced unauthorized access to its website server, resulting in the installation of malware designed to intercept customer payment card information and personal data over several months. The compromise affected names, addresses, card details, security codes, and website credentials, though PayPal transactions only exposed account credentials without card data. The company removed the malicious code, migrated its website to a PCI-compliant platform, conducted security scans, and notified affected customers. Individuals were advised to reset passwords and offered complimentary identity protection services following reports of fraudulent charges linked to the breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In October 2014, unauthorized individuals gained access to Lime Crime's website server and installed malware designed to intercept customer payment card data and personal information. The malicious code remained active on the cosmetics company's e-commerce platform until February 15, 2015, affecting customers who made purchases during this four-month period. The compromised data included names, billing addresses, payment card account numbers, expiration dates, and security verification codes. Customers who created accounts on Lime Crime's website also had their usernames and passwords exposed. PayPal users experienced partial compromise, with website credentials potentially accessed but payment card details remaining secure due to PayPal's external transaction processing. The breach resulted in confirmed fraudulent charges on customer accounts, as acknowledged in Lime Crime's February 24, 2015 security notification.

Lime Crime responded by deleting the malicious code from their systems and migrating their website to a new PCI-compliant hosting platform. Security professionals conducted vulnerability scans on the reconfigured infrastructure, verifying no residual threats remained. The company initiated customer notifications through their website, advising all affected individuals to reset their account passwords immediately. As remediation, Lime Crime offered impacted customers complimentary identity protection services and fraud resolution support for twelve months. The volume of inquiries following the disclosure temporarily overwhelmed customer service channels, causing delayed email response times. Forensic analysis confirmed the malware specifically targeted payment card transactions processed directly through Lime Crime's website between October 4, 2014, and February 15, 2015.
