Report URI Resources

Case Studies

Customer stories, notable attacks, and organisations running a Content Security Policy in production.

The official Have I Been Pwned logo.

Have I Been Pwned

Learn how Have I Been Pwned uses Report URI to monitor their site for Malicious JavaScript and unauthorised Data Exfiltration!

Read More

The Instructure logo.

XSS
Instructure Canvas Breach

A support ticket containing a linked file reached 275 million student records — and four days passed before anyone noticed the stolen session.

Read More

The Google logo.

Google

Gmail, YouTube, Cloud Console and Google Drive all enforce a Content Security Policy, with Trusted Types on top. Read off their live response headers.

Read More

The Bybit logo.

Bybit Supply Chain Attack

$1.46 billion — the largest theft in the asset class's history — began with a modified JavaScript file, served to a single wallet and removed two minutes later.

Read More

The United States Courts logo.

US Courts Cryptojacking Attack

The United States Courts were infected with Cryptojacking Malware that used visitor's browsers to mine Cryptocurrency for the attackers.

Read More

The Newegg logo.

Newegg Magecart Attack

Eight lines of JavaScript skimmed Newegg’s checkout for 35 days in 2018 — the same group as British Airways, with the code cut to a third of the size.

Read More

The official Paddle logo.

Paddle

Paddle are a Payment Infrastructure Provider and use Report URI to help meet their obligations under the new PCI DSS 4.0!

Read More

The official Ticketmaster logo.

Ticketmaster Magecart Attack

Ticketmaster were targeted by Magecart in an attack via a 3rd-party dependency. Learn how Report URI could have helped and saved millions in damages.

Read More

XSS
Operation RoundPress

A spearphishing email injected JavaScript into the victim’s open webmail page. Nothing touched disk for endpoint tooling to find.

Read More

Polyfill.io Supply Chain Attack

A dependency 100,000 sites trusted changed hands and started serving malicious code. Nothing on any of those sites changed.

Read More

The GitHub logo.

GitHub

GitHub's entire script-src is a single hostname. They shipped their first policy in 2013 with a wildcard in it and spent three years tightening it in public.

Read More

The European Space Agency logo.

European Space Agency Magecart Attack

The ESA was infected with Magecart which resulted in the organisation having to take down certain infrastructure.

Read More

The Dropbox logo.

Dropbox

Four posts in 2015 on getting a policy into production, including the report noise that nearly stopped them. The policy is still in their headers today.

Read More

The Ivanti logo.

XSS
Ivanti EPM Device Name XSS

An unauthenticated request wrote JavaScript into a device name, to fire later in an admin dashboard with authority over every managed endpoint.

Read More

The Magento logo.

CosmicSting Magento Attacks

CVE-2024-34102 was used to skim 4,275 Adobe Commerce and Magento stores. Applying the patch did not stop it, because the stolen keys stayed valid.

Read More

The Volusion logo.

Volusion Supply Chain Attack

One modified platform library reached 6,589 merchant stores. None of them were breached, and 239,000 cards were later sold.

Read More

The official Shoptet logo.

Shoptet

Shoptet is an e-commerce platform used by more than 40,000 active online stores across the Czech Republic, Slovakia, and Hungary.

Read More

The official Ticketmaster logo.

ICO Cryptojacking Attack

The Information Commissioner's Office was the victim of a Cryptojacking Attack that could have been detected and even stopped using Report URI.

Read More

XSS
Zimbra Token Theft

Exploited as a zero-day for six weeks, then again after the patch made it public. The payload stole the authentication token, not the mail.

Read More

The GOV.UK logo.

GOV.UK

They ran CSP in report-only for years before enforcing it in Summer 2023, and published the decision, the manual and the policy source along the way.

Read More

The REPAY logo.

REPAY

REPAY Holdings Corporation is a leading payments technology company that delivers secure, frictionless payment solutions across multiple industries.

Read More

The Claire’s logo.

Claire’s Magecart Attack

A day after Claire’s closed 3,000 stores for lockdown, attackers registered their exfiltration domain. The skimmer ran for six to seven weeks, disguised as an image request.

Read More

The X logo.

Twitter and X

In 2013 Twitter published why their own front page had too much inline JavaScript for CSP. Today x.com forbids inline event handlers outright.

Read More

The British Airways logo.

British Airways Magecart Attack

Magecart targeted British Airways to gain access to significant quantities of PII and PCD, resulting in 8-figure fines for the organisation.

Read More

The login.gov logo.

login.gov

The US federal login page runs the cleanest policy in this research — no unsafe-inline, no unsafe-eval — and you can read its source in public.

Read More