(Pierluigi Paganini – Security Affairs) Since February 27, a large-scale campaign has defaced over 7,500 Magento sites, targeting e-commerce platforms, global brands, and government services. According to cybersecurity firm Netcraft, attackers placed plaintext defacement files across more than 15,000 hostnames, directly compromising affected infrastructure. “Netcraft detected this campaign’s first activity on 27 February 2026, with newly compromised sites continuing to appear at the time of writing.” reads the report published by Netcraft. “Netcraft is tracking this campaign’s activity over 15,000+ hostnames (subdomains) within ~7,500 unique domains. Defacements were uploaded as plaintext files hosted directly on affected infrastructure.”. Defacement pages show handles like L4663R666H05T, Simsimi, Brokenpipe, and Typical Idiot Security, often with “greetz” lists typical of defacement culture. – 7,500+ Magento sites defaced in global hacking campaign
7,500+ Magento sites defaced in global hacking campaign
Related articles



