CSIDB logo
Incident

Lindt

Incident posture

Attack window
Mar 2026
Location
Switzerland
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 04:21

Linked entities

Victim
Lindt
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2026
Discovered
Undetermined
Disclosed
Mar 2026
Resolved
Pending

Summary

A mass defacement campaign compromised thousands of Magento sites, including subdomains and regional storefronts of global brands such as Lindt, by exploiting an unauthenticated file upload vulnerability in the platform’s REST API. Attackers placed plaintext defacement files bearing the handle “Typical Idiot Security” on affected hosts, with some files containing brief political messages, and the campaign also hit government, university, nonprofit and Trump Organization domains. Security researchers identified the underlying flaw, dubbed PolyShell, which affects all Magento Open Source and Adobe Commerce versions up to 2.4.9‑alpha2 and could allow unauthenticated upload of executables, though no active exploitation has been observed yet.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The defacement campaign that targeted Magento sites began approximately three weeks before the article’s publication date of 7 March 2026. Netcraft reported that over 7,500 Magento installations were compromised, with defacement files placed on more than 15,000 hostnames. Among the affected entities were global brands such as Lindt, whose subdomains, regional storefronts, and staging environments were hit, and a few production‑facing pages were briefly defaced. The attacker uploaded plaintext files that displayed the handle “Typical Idiot Security” and, on 7 March 2026 only, included political messages referencing recent geopolitical conflicts. Most of the incidents were logged in the Zone‑H defacement archive under the account ‘Typical Idiot Security’, linking the handle to the threat actor. The campaign’s timing suggests the political messages were opportunistic and not the primary motive.

Netcraft and Sansec identified the likely entry point as an unauthenticated file upload vulnerability affecting Magento Open Source, Magento Enterprise/Adobe Commerce, and Adobe Commerce deployments with Magento B2B. Sansec named the flaw PolyShell and noted it impacts all Magento Open Source and Adobe Commerce versions up to 2.4.9‑alpha2. The vulnerable code has been present since the initial Magento 2 release and was patched in the 2.4.9 pre‑release branch as part of advisory APSB25‑94, but no isolated patch exists for current production versions. While Sansec has not observed active exploitation of PolyShell in the wild, the exploit method is already circulating and automated attacks are anticipated. This vulnerability permits unauthenticated actors to upload arbitrary files, which aligns with the observed placement of defacement content.

For Lindt, the defacement appeared as brief alterations of web content on the affected subdomains and storefronts before the original material was restored. The same pattern was observed across other targeted brands, government services, university domains in Latin America and Qatar, international non‑profits, and domains associated with the Trump Organization. Netcraft’s reporting and the Zone‑H entries provide the primary public record of the incident’s detection and scope. No further specifics regarding Lindt’s internal response, such as patch application or forensic analysis, are detailed in the supplied source. Consequently, the narrative is limited to the confirmed facts of the campaign’s timing, scope, attacker actions, and the brief nature of the defacement observed on Lindt’s assets.

Sources

Sources available to members: 1 source.

CSIDB