At least 100 Sothebys real-estate-related sites were infected with malicious skimmers. The skimmer code harvests information that victims load into contact pages requesting a home showing, including names, emails and phone numbers. It then sends them to a malicious collection server (https://cdn-imgcloud[.]com/img), hosted on a content delivery network. The information could be used for convincing follow-on phishing and other social-engineering attacks. Brightcove says the malicious video in question was housed in third-party storage.”]
Source: https://threatpost.com/data-skimmer-sothebys-real-estate-websites/177347/