← Back to blog

News

CosmicSting, One Year Later: The Breach That Reshaped Magento Security

June 18, 2025 - by Alexandru-Manuel Carabus

A year after CosmicSting was disclosed, the damage is measurable: thousands of stores hacked, big brands skimmed, and one uncomfortable lesson about patch speed.

A sealed navy secure block with a thin hairline crack leaking faint light and a small orange glow at the fracture, illustrating a store quietly breached.

CVE-2024-34102, better known as CosmicSting, was disclosed in June 2024. A year on, it is fair to call it the worst Magento security event in years, and the fallout tells you more about how stores get owned than any checklist can.

What CosmicSting was

CosmicSting scored 9.8 out of 10 on the CVSS severity scale. It let an attacker read a store is secret cryptographic key, then use that key to mint a valid API token, and from there insert a payment skimmer through CMS blocks. The result was full access to private customer data and the checkout page.

The scale of the damage

According to Sansec, at least 4,275 online stores were hacked in the year following disclosure, and roughly five percent of all Adobe Commerce and Magento stores ended up with a skimmer on their checkout at one point. The victim list included large brands such as Swatch, Ray-Ban, Cisco, Carlsberg, Segway and Whirlpool. This was not a small-store problem.

Why patched stores still got hit

Here is the detail that caught many teams out. Applying the patch was not enough. If the secret key had already leaked, attackers could keep using it after patching. Stores that patched but did not rotate their encryption key stayed exploitable. Security was a two-step job, and the second step was quietly skipped on thousands of sites.

The lasting lesson: patch speed is a business metric

The stores that came through clean shared one habit: they patched within hours or days, not weeks, and they rotated keys afterward. Time-to-patch turned out to be the difference between a normal week and a skimmer on your checkout. It is the clearest argument we know for treating maintenance as an operating cost, not an optional extra.

What to check now

If you ran a store through 2024, confirm the CosmicSting patch is applied, your encryption key has been rotated since, and you have file-integrity monitoring on the checkout path. If you are not sure where you stand, book a free strategy call with LIQUIDLAB and we will help you check.