CSIDB logo
Incident

Garmin

Incident posture

Attack window
Sep 2019
Location
South Africa
Status
Historical
CIA posture
Available to members
Updated
2026-02-09 11:18

Linked entities

Victim
Garmin
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach impacted a South African online store operated by Garmin, where attackers deployed card-skimming technology to intercept customers’ payment and personal information during transactions. The compromised data included full credit card details, addresses, phone numbers, and email addresses, affecting fewer than 6,700 individuals. The incident stemmed from a third-party contractor managing the Magento-based portal, which had known vulnerabilities enabling prolonged malware operation. The company isolated the breach to the regional site, took the portal offline, and notified relevant authorities. No other global systems or customer data were affected by this intrusion.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around September 12, 2019, Garmin experienced a security breach affecting customers who used its South African online store at shop.garmin.co.za. Attackers deployed card-skimming technology to intercept customers' payment details as they entered information during transactions. The compromised data included full credit card information, home addresses, phone numbers, and email addresses—sufficient to enable fraudulent card activity. Garmin's investigation determined the incident impacted fewer than 6,700 customers. The breach stemmed from a third-party contractor responsible for operating the South African web portal, which utilized the Magento e-commerce platform known for documented security vulnerabilities. Attackers exploited these weaknesses to implant skimming malware capable of operating undetected for extended periods. Garmin confirmed the breach was geographically isolated to South Africa with no impact on other regional systems or customer data.

Garmin responded by immediately shutting down the compromised South African web portal upon detecting the breach. The company notified relevant regulatory authorities and initiated direct communications with affected customers, advising them to monitor their payment card statements for unauthorized transactions. No evidence suggested broader compromise of Garmin's corporate networks or primary customer databases. The incident highlighted risks associated with third-party-operated systems, as the contractor-managed Magento instance became the intrusion vector. Forensic analysis confirmed the skimming operation exclusively targeted data entered during checkout processes on the South African storefront. Garmin did not disclose the exact timeframe during which attackers harvested data but emphasized containment through the portal's deactivation and ongoing coordination with payment processors to mitigate fraud risks.

Sources

Sources available to members: 1 source.

CSIDB