Blames firm that runs store's backend ops; no details on what was accessed, when or how FRAMINGHAM – Mozilla shuttered its online store late Tuesday after finding out that the firm it hired to run the backend operations of the company’s e-tailing business had suffered a security breach.It was unclear whether the vendor, St. Louis-based GatewayCDI, which bills itself as a “promotional products distributor and incentive company,” notified Mozilla or whether the browser maker found out about the breach some other way.“Today, Mozilla discovered that GatewayCDI, the third-party vendor entrusted to run the backend of the Mozilla Store, suffered a security breach,” Mozilla said in a warning on its Web site. “Once notified, we took the immediate preventative step of shutting down the Mozilla Store to ensure that no additional users could be compromised.”Mozilla also took the international edition of its e-store offline as a precaution, although that effort is maintained by a separate partner. Late Tuesday, both stores displayed messages that they were “closed for maintenance;” neither message, however, spelled out the reason.The stores sell promotional items, such as T-shirts, backpacks, coffee mugs and mouse pads emblazoned with company logos, as well as the Firefox browser on CD. Mozilla’s announcement did not detail the extent of the breach, what information hackers might have accessed or stolen, or how the breach happened. GatewayCDI was not available late Tuesday, and there was no notice on its site that it had sustained a breach.“Mozilla immediately reached out to GatewayCDI and encouraged them to quickly inform individuals whose data had been compromised,” said Mozilla. “GatewayCDI is currently investigating their systems and determining the cause and extent of the breach.”According to Mozilla, its online store may be closed for some time. “The store will only be reinstated once we have a satisfactory assurance of ongoing login security and data privacy,” the company said.The incident was the first for Mozilla, an open-source developer that prides itself on its operational transparency.The company’s Firefox accounts for about 22.5% of the browser market, according to the most recent data from Web metrics firm Net Applications. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe