With less than a week to go until Magento 1 End of Life, based on our recent eCommerce “universe” security scan, there are over 218,000 Magento 1 sites yet to migrate.
In fact, only 2,576 Magento 1 websites migrated off Magento 1 last month - the numbers are a lot lower than the payments industry leaders would be happy with.
We conduct monthly monitoring of the security status of the websites within our eCommerce “universe” dataset - last month we checked over 8.4 million sites within our universe scan and these are the summary results, with a particular focus on Magento 1:
Total number of Magento 1 sites being monitored: 218,722
CRITICAL RISK sites: 3,166
(Note: CRITICAL RISK means the site is hacked and payment data is being actively stolen right now)
CRITICAL Risk Magento 1: 2,040
Most prevalent card harvesting malware: Skimmers (over 3,000 found in 3,166 hacked sites)
Sites at HIGH RISK of being hacked: 708,451
HIGH RISK Magento 1: 206,021
The facts are that:
Both Visa and Mastercard have said that they will not accept Magento 1 sites as being PCI Compliant, without compensating controls.
So what does this mean for Magento 1 websites?
Migration is a challenge - we understand, from speaking with a large number of merchants, that migration from Magento 1 to Magento 2 is the easiest option, but even then it needs careful planning, and consideration to ensure that the site is successfully migrated across. Without losing the years of investment in SEO and so on… In short, migration is vital, but it needs time, planning and care.
Our advice is to secure and insure.
Your business may not be migrating before the End of Life deadline in a week, but you can take steps to ensure you are mitigating the risks. We’re here to help - we have well over a decade experience in helping eCommerce businesses defend against criminals and we’d be very happy to help you too.
For more information check out our Foregenix WebScan Industry Update June 2020 and join our
Magento 1 End of Life: How to Avoid Card-harvesting Malware Breaches webinar on 29th Jun 2020.