Menu
Browse

Cyber Incident Victim: Nippon Ichi Software America

Date:

Jan 2018

Location:

United States of America

Summary

NIS America experienced a cybersecurity breach where attackers compromised customer payment card details and address information through a malicious process injected into its online store checkout pages, affecting transactions made via credit card over a multi-week period; PayPal users were unaffected. The company confirmed it does not store full payment card data or CVV codes, advised customers to change passwords and monitor financial accounts, and offered $5 discount codes as compensation while emphasizing enhanced security measures to prevent future incidents.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The NIS America data breach occurred between January 23 and February 26, 2018, affecting the company's online stores at store.nisamerica.com and snkonlinestore.com. Attackers implanted a malicious process on the checkout page that intercepted customers' payment card details and address information during transactions. This skimming operation captured data from new orders placed with credit cards but did not compromise transactions processed through PayPal. The breach remained undetected until February 26, when NIS America security personnel identified the malicious script, which had been operational for over a month. The compromised data included full payment card information and shipping addresses entered during the checkout process for orders placed within the attack window.

Cyber Incident Image

NIS America notified affected customers via email shortly before March 1, 2018, confirming the breach timeline and scope. The company emphasized that its user account system did not store complete payment card details—only the last four digits of credit cards—and excluded CVV codes or expiration dates. As remediation, NIS America advised customers to change account passwords, monitor financial statements for fraudulent activity, and remain vigilant against phishing attempts. The company offered $5 discount codes for future purchases as compensation and reopened its stores after implementing undisclosed security improvements. No evidence suggested historical order data was compromised, as the attack exclusively targeted new transactions during the specified period. NIS America acknowledged the breach's impact on customer trust and stated its commitment to enhancing security measures to prevent recurrence.

Sources
Sources available to members
1 source