Menu
Browse

Picreel

Primary URL Location Industry
picreel[.]com
Country United States of America
Technology Icon
Technology
Profile

Picreel, operating under the alias Picreel and headquartered in the United States of America, provides secondary website code that is integrated into a wide range of online platforms to enable additional functionality such as form handling or widget deployment. The company's technology is designed to be embedded directly into client websites, allowing it to run alongside primary site scripts and interact with user‑entered data. Because its code is deployed on numerous third‑party sites, Picreel serves a broad market of web‑based businesses seeking to enhance site features without developing custom solutions. Its headquarters in the United States situates it within a major hub for technology firms and digital service providers. No explicit details about its founding date, ownership structure, or parent‑subsidiary relationships are available in the supplied information.

The 2019‑05‑12 incident revealed that Picreel’s servers were compromised as part of a supply‑chain attack targeting providers of secondary website code, enabling attackers to inject malicious scripts across thousands of websites. These injected scripts were crafted to capture all user input entered into form fields—including payment details, passwords, and contact information—and exfiltrate the harvested data to a server located in Panama. While some of the malicious scripts failed to execute due to coding errors or limited deployment scope, the breach demonstrated the potential reach of Picreel’s code distribution network. Investigations noted that one affected third‑party service provider disabled its compromised content delivery network, though no direct breach of that provider’s infrastructure was found. The episode underscored a broader trend in which attackers exploit dependencies on external code providers to harvest sensitive data from diverse web forms at scale.

Incidents
Linked incidents available to members
1 incident