Update 10/03/26 – 08:26 pm (IST): After publication, L4663R666H05T contacted me and shared additional details about the campaign. He said he did not need to hijack anybody’s account and described the activity instead as “random cookie” or “cookie injection with random string.” He also claimed that he and two others did not steal any data and that the operation was limited to uploading TXT files as markers on compromised Magento/Adobe Commerce sites.

The same source said the affected websites were hosted in AWS environments, which in his view made it unlikely or impossible to upload a backdoor and trigger remote code execution in this case. He further claimed that such outcomes would have been more likely on Apache setups, while on Nginx they would only work sometimes. PiunikaWeb has not independently verified those technical claims.

According to the source, the campaign defaced more than 14,000 websites in around two days. He claimed the group had compiled a list of roughly 200,000 active Magento sites and then used a bot to run the process at scale. He added that his main targets were Israeli or otherwise large websites, and said the Chilean sites highlighted earlier were likely swept up randomly from that larger list.

The source further said the campaign was mainly carried out for recognition on Zone-H. PiunikaWeb has not independently verified the claimed scale of the operation, the targeting criteria, or the identity of the person who made these statements.


Original unedited article published on March 10, 2026, follows:

Websites connected to big names like Toyota, ASUS, and UNICEF are showing clear signs of being breached. Visitors to certain parts of these sites can now find odd text files that were not supposed to be there.

These files sit in specific folders on Magento e-commerce platforms. They carry signatures from a user who goes by L4663R666H05T, along with Typical Idiot Security and a few others. Some of the notes even include messages touching on the conflict in the Middle East.

Security researcher Germán Fernández, who posts on X as @1ZRR4H, first highlighted the issue with Chilean online stores. He shared screenshots showing compromises at sites for Entel, Bice Vida, Colun, CasaIdeas, and several clothing brands like Volcom and Fila.

chile-websites-hacked-report-x

The same pattern soon showed up on international targets. Staging versions of Toyota and ASUS sites, plus the UNICEF supply portal, apparently have similar marker files. Here are the screenshots shared by Fernández in a follow-up post:

ASUS — Compromised Page
asus-page-compromised
Toyota — Compromised Page
toyota-page-compromised
UNICEF — Compromised Page
unicef-page-compromised
ACE — Compromised Page
ace-co-il-page-compromised

Other researchers, including MalwareHunterTeam, Ricardo Monreal, @joy_dragon, TIAL, and chum1ng0 have been reposting the news. What the screenshots suggest is straightforward. The attackers got in, uploaded simple TXT files as their calling card, and left. No major defacement of the homepages has appeared at the time of this writing.

This looks tied to a known vulnerability in Adobe Commerce and Magento known as SessionReaper or CVE-2025-54236. It lets people hijack accounts on unpatched sites. Adobe pushed out the patch in September 2025. Even so, a quick scan shows that lots of stores have not applied it. That leaves the door wide open for crews like this one.

The group behind this seems to be an Indonesian crew that enjoys leaving their mark on websites. They have done similar things before, and their claims sometimes show up on archives like Zone-H and defacer.id. For now, the activity feels more like showing off than stealing customer data, though that risk remains real.

Chilean brands took a noticeable hit in this latest wave. Many everyday shopping sites there now carry these digital signatures.

Anyone running a Magento store should check those media folders right away and make sure their platform is fully patched. These kinds of campaigns spread fast once attackers start scanning for weak spots. The files are still visible on several of the staging sites today, which makes it easy for anyone to verify.

NOTE: If you are close to this matter and have corrections, updates, or additional context to share, feel free to reach out at [email protected].

Featured image generated with AI

We stand out from the tech-media crowd because we break news stories; we mainly bring you stuff that you won’t find anywhere in the mainstream tech media. Our stories have been picked up by some of the world’s most popular websites and media outlets—more info is available here.

Dwayne Cubbins
2871 Posts

I cover fast-moving stories across apps, online platforms, and everyday tech — phones, wearables, consoles, and whatever else people are fighting with this week. Bugs, rollouts, scams, policy enforcement, and the occasional internet-culture rabbit hole are all fair game. My goal is simple — make confusing tech news readable. When I'm not working, I'm working out or chilling with my dog. Got a tip? You can find me on X @dcubbins.

Next article View Article

Some Instagram users unable to see posts when using search function [Updated]

Update 28/04/26 - 10:46 am (IST): It appears the Instagram search glitch has resurfaced, with a fresh wave of users taking to Reddit to report that the search...
Apr 28, 2026 2 Min Read