CSIDB logo
Incident

Warner Music Group

Incident posture

Attack window
Apr 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
Warner Music Group
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Warner Music Group experienced a web skimming attack compromising multiple US-based e-commerce platforms hosted by an external service provider. Malicious code injected into online stores harvested customers' personal and payment information during checkout, including names, contact details, addresses, and payment card data with security codes. The breach occurred over several months, though PayPal transactions remained unaffected. The company did not disclose specific impacted stores, creating uncertainty for customers across its portfolio of music studios. Affected individuals were offered complimentary credit monitoring services following the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Warner Music Group experienced a web skimming incident impacting several US-based e-commerce websites hosted and supported by an external service provider. The breach occurred between April 25, 2020, and August 5, 2020, during which unauthorized third parties injected malicious code to capture customer payment information. This form of attack, commonly referred to as "magecart," compromised data entered by users after placing items in shopping carts on affected sites. Exfiltrated information included names, email addresses, telephone numbers, billing and shipping addresses, and payment card details such as card numbers, CVC/CVV codes, and expiration dates. Warner Music confirmed PayPal transactions were not vulnerable to the skimming operation. The company did not disclose specific compromised storefronts or identify affiliated music studios impacted by the breach, leaving customers unable to self-assess their exposure risk due to the absence of individualized notifications or a published list of affected properties.

Warner Music filed a data breach notification with the California Office of the Attorney General on September 3, 2020, advising customers of the four-month intrusion window and potential data compromise. The company offered impacted individuals free credit monitoring services through Kroll, with enrollment details included in the notification letter. No technical details regarding the initial intrusion vector, malware deployment methods, or containment procedures were publicly disclosed. The incident exposed limitations in third-party vendor security controls, as the breach originated within infrastructure managed by the external service provider supporting Warner’s e-commerce operations. Financial ramifications, regulatory penalties, and the total number of affected customers remained unquantified in available disclosures.

Sources

Sources available to members: 1 source.

CSIDB