Cyber Incident Victim: giftstore.co.il
Date:
Oct 2014
Location:
Israel
Summary
An Israeli online gift store experienced a significant data breach compromising customer credit card information, which was subsequently leaked by a Saudi hacker. The stolen financial records were publicly exposed online, leading to fraudulent transactions and heightened risks of identity theft for affected individuals. The incident highlighted vulnerabilities in the retailer's payment systems and underscored broader concerns regarding e-commerce security practices. Customer trust was severely impacted due to the unauthorized disclosure of sensitive personal and financial data.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On October 27, 2014, cybersecurity news outlet Hackread reported a significant data breach impacting Israeli citizens through the compromise of giftstore.co.il, an online retail platform. A hacker using the alias "0xOmar," claiming Saudi Arabian affiliation, leaked thousands of Israeli credit card records obtained from the site. The attacker publicly disclosed approximately 7,000 credit card details in an initial release, asserting possession of over 20,000 records overall. Exposed data included full card numbers, expiration dates, CVV security codes, cardholder names, billing addresses, and phone numbers. The hacker utilized Pastebin to publish the stolen financial information alongside political statements justifying the attack as retaliation for Israeli military operations in Gaza. Specific threats accompanied the leak, with 0xOmar demanding Israel cease its Gaza campaign within 48 hours to prevent further data releases.

Israeli financial institutions rapidly mobilized to assess the breach's validity, cross-referencing leaked card details with bank records to confirm their authenticity. This verification confirmed active cards among the leaked data, escalating concerns about fraudulent transactions and identity theft risks. The breach triggered widespread alarm across Israeli financial sectors and among affected citizens, prompting urgent card cancellation and reissuance procedures. 0xOmar's political messaging framed the attack as part of the broader Arab-Israeli conflict, explicitly linking the cyber operation to ongoing military tensions. The incident underscored vulnerabilities in regional e-commerce security practices while demonstrating how geopolitical conflicts increasingly extend into cyber operations targeting civilian financial infrastructure. No subsequent reports confirmed whether the hacker carried out additional data releases following the initial disclosure.
