Cyber Incident Victim: Garmin
Date:
Sep 2019
Location:
South Africa
Summary
A cybersecurity breach impacted a South African online store operated by Garmin, where attackers deployed card-skimming technology to intercept customers’ payment and personal information during transactions. The compromised data included full credit card details, addresses, phone numbers, and email addresses, affecting fewer than 6,700 individuals. The incident stemmed from a third-party contractor managing the Magento-based portal, which had known vulnerabilities enabling prolonged malware operation. The company isolated the breach to the regional site, took the portal offline, and notified relevant authorities. No other global systems or customer data were affected by this intrusion.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around September 12, 2019, Garmin experienced a security breach affecting customers who used its South African online store at shop.garmin.co.za. Attackers deployed card-skimming technology to intercept customers' payment details as they entered information during transactions. The compromised data included full credit card information, home addresses, phone numbers, and email addresses—sufficient to enable fraudulent card activity. Garmin's investigation determined the incident impacted fewer than 6,700 customers. The breach stemmed from a third-party contractor responsible for operating the South African web portal, which utilized the Magento e-commerce platform known for documented security vulnerabilities. Attackers exploited these weaknesses to implant skimming malware capable of operating undetected for extended periods. Garmin confirmed the breach was geographically isolated to South Africa with no impact on other regional systems or customer data.

Garmin responded by immediately shutting down the compromised South African web portal upon detecting the breach. The company notified relevant regulatory authorities and initiated direct communications with affected customers, advising them to monitor their payment card statements for unauthorized transactions. No evidence suggested broader compromise of Garmin's corporate networks or primary customer databases. The incident highlighted risks associated with third-party-operated systems, as the contractor-managed Magento instance became the intrusion vector. Forensic analysis confirmed the skimming operation exclusively targeted data entered during checkout processes on the South African storefront. Garmin did not disclose the exact timeframe during which attackers harvested data but emphasized containment through the portal's deactivation and ongoing coordination with payment processors to mitigate fraud risks.
