Hackers defaced 7,500 Magento sites since Feb 27, uploading files across 15,000 hostnames, mostly opportunistic attacks.
Since February 27, a large-scale campaign has defaced over 7,500 Magento sites, targeting e-commerce platforms, global brands, and government services. According to cybersecurity firm Netcraft, attackers placed plaintext defacement files across more than 15,000 hostnames, directly compromising affected infrastructure.
“Netcraft detected this campaign’s first activity on 27 February 2026, with newly compromised sites continuing to appear at the time of writing.” reads the report published by Netcraft. “Netcraft is tracking this campaign’s activity over 15,000+ hostnames (subdomains) within ~7,500 unique domains. Defacements were uploaded as plaintext files hosted directly on affected infrastructure.”
Defacement pages show handles like L4663R666H05T, Simsimi, Brokenpipe, and Typical Idiot Security, often with “greetz” lists typical of defacement culture.

EXPLORE MORE
Canadians warned about social media ban leading to privacy violations, digital ID
(LifeSiteNews) — One of Canada’s top constitutional freedom groups warned that a…
Wanted: Suspects for Robbery/Sexual Assault in the 9th District
On Saturday, April 25, 2026, at 4:40 a.m., several males forced their…
Interpol – Operation Synergia III leads to 45,000 malicious IPs dismantled and 94 arrests worldwide
INTERPOL dismantled 45,000 malicious IPs and servers and arrested 94 suspects in…
U.S. CISA adds a flaw in n8n to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in…
Missing Person Tiffany Jackson from the 39th District
The Philadelphia Police Department is requesting the public’s assistance in locating 45-year-old…
Frank Wright: Henry Nowak’s murder is ‘emblematic’ of the ‘murder’ of Britain
(LifeSiteNews) — LifeSite’s Frank Wright called the murder of Henry Nowak, who…
Initial investigation indicates attackers may exploit unauthenticated file uploads in some Magento environments, affecting Open Source, Enterprise, and B2B editions. Netcraft researchers observed only text defacements. While Adobe released security bulletins, these do not appear directly linked. The campaign resembles the October 2025 SessionReaper attack, with successful test uploads on Magento Community 2.4.9-beta1, highlighting Magento’s widespread global use.
The campaign hit high-profile brands like Toyota, Fiat, Asus, Bandai, FedEx, and others, mostly on subdomains, staging, or regional sites, with some production sites briefly affected. The campaign hit Government and academic domains in Latin America and Qatar, and non-profits. Attackers also defaced several Trump Organization domains, likely as part of broad opportunistic exploitation rather than targeted attacks.
“Given the scale of the activity and the number of high-profile domains affected, this campaign highlights how widely deployed web platforms can become a force multiplier for attackers conducting opportunistic exploitation.” concludes the report.
