CSIDB logo
Incident

MyCause

Incident posture

Attack window
Jun 2014
Location
Australia
Status
Historical
CIA posture
Available to members
Updated
2026-01-18 23:02

Linked entities

Victim
MyCause
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers compromised an Australian charity donation platform, stealing credit card details of up to 12,000 donors and using the information for fraudulent transactions across multiple continents, including purchases in the United States, Europe, and the United Arab Emirates. The breach affected users who contributed through the website during a two-month period, with individual losses reaching thousands of dollars, while the organization maintained its security met industry standards but initiated enhanced anti-fraud measures following the incident. Victims expressed distress over financial harm incurred while supporting charitable causes such as cancer support and youth sports funding.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In June and July 2014, an international hacking operation compromised the MyCause charity website, exposing credit card details of up to 12,000 donors who contributed through the Australian fundraising platform. The attackers stole financial data during the two-month breach window and subsequently used it to conduct fraudulent transactions across multiple regions, including the United States, Europe, and the United Arab Emirates. MyCause founder Tania Burstin confirmed the breach after fraudulent activity was detected on victims' accounts, noting the website's security had met industry compliance standards prior to the incident. The attackers specifically targeted MyCause as a recognized charity platform, exploiting its public profile to access donor information. Burstin stated the organization was enhancing its anti-fraud protections in response, though no technical details about the attack vector or intrusion methods were disclosed.

The breach caused direct financial harm to donors, with at least two confirmed cases illustrating the scope of losses. Canberra resident Emma Barnes incurred a fraudulent $3,000 charge at Walmart in the United States after donating to support a friend's family affected by cancer. Melbourne donor Sergio Correa suffered over $1,500 in unauthorized charges following his contribution to fund a sports team's competition in China. Both victims expressed frustration that their charitable actions resulted in financial exploitation, with Correa indicating he would exercise greater caution with future online donations. MyCause did not disclose whether charities or fundraiser recipients experienced secondary impacts from the breach. The incident remained under investigation with no attribution to specific threat actors or details about containment measures beyond the planned security enhancements.

Sources

Sources available to members: 1 source.

CSIDB