Blog

Recent Breach Targeted MyPillow And Amerisleep Customer Data

By Mersad • April 13, 2019

If you've purchased bedding from either MyPillow or Amerisleep, your data may have been compromised. These companies are two popular mattress and bedding merchants operating in the US. This is according to a recent report coming to us from RiskIQ. The hacking group Magecart appears to be behind both breaches, which is bad news for both companies and their customers.


That is because Magecart is one of the most talented and active hacker groups on the scene today, having launched a number of successful attacks against high profile targets that have included Ticketmaster, Feedify, Shopper Approved, Newegg, and British Airways.


MyPillow entered into Magecart's crosshairs in October 2018, when the group compromised MyPillow's e-commerce and sales platform and began skimming credit card information submitted by the company's customers. The group also registered a similar domain, mypiltow.com and utilized 'Let's Encrypt' to implement an SSL certificate. Unsuspecting visitors to the site had no idea they were on a domain controlled by the hacking group.


According to RiskIQ researcher Yonathan Klijnsma, "...this type of domain registration typosquatting means that the attackers had already breached MyPillow and started setting up infrastructure in its name."


Within a month's time, the hacking group moved onto the second phase of its attack, registering a new website called livechatinc.org, which mimicked the Live chat used by MyPillow. With a poisoned script already running inside the company's infrastructure, Magecart was able to mimic the genuine tag used by the live support service. This was so that by all outward appearances, customers believed they were chatting with an actual MyPillow employee.


The attack on AmeriSleep dates back a bit further to April 2017, but followed a similar pattern. The skimmer remained in operation between April through October of 2017. The company rid themselves of Magecart's malicious software, only to come under attack again in December 2017.


In both cases, the skimmer domains have been taken offline, but both companies are still dealing with the malicious code injection issues. RiskIQ notes that given Magecart's history, even when both companies clear their servers of malicious code, they're likely to be re-infected in short order. Watch your credit card statements if you've made a purchase from either company.


Used with permission from Article Aggregator

Related Posts

By BayPointe Technology • October 7, 2026
Learn what secure remote IT support requires, from trusted help requests and controlled access to device standards, session records, and onsite escalation.
By BayPointe Technology • September 30, 2026
Find out whether your business backups can support recovery. Plan restore tests, measure results, and address gaps before an outage disrupts work.
By BayPointe Technology • September 23, 2026
Help employees recognize phishing emails, verify unusual requests, and report concerns with a practical process for Northeast Ohio businesses.
Stressed man at desk with hand on face, holding glasses near a computer and moving boxes
By BayPointe Technology • September 16, 2026
Recurring IT issues, growing support demands, or unclear security responsibilities? Learn when your Northeast Ohio business should consider managed IT services.
Blue illuminated curved metal structure with repeating ribbed arches
By BayPointe Technology • September 9, 2026
Plan office-move IT tasks, including internet installation, cabling, phones, equipment, vendor coordination, and opening-day readiness checks.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256