E commerce Payment Page Card Skimming (Magecart) and Protection
Web based card skimming (Magecart) is when an attacker places hidden code on the payment page to steal card details, and it can last for months undetected. How it works, CSP and script auditing for site owners, the legal dimension and protection for shoppers.
Quick answer: Web based card skimming (also known as Magecart) is when an attacker places hidden code on an e commerce site's payment page and steals the card details customers enter. The site keeps working normally, the payment succeeds, and neither the customer nor often the site owner notices anything is wrong; this is why these attacks can last for months. As a site owner, to protect yourself, tightly control third party scripts, apply a content security policy (CSP) on the payment page, keep your e commerce platform and plugins up to date, monitor file integrity and run regular security scans. As a shopper, protecting your card with a virtual card or a low limit card reduces the risk.
When you enter your card details on an e commerce site and hit pay, you assume that information goes only to the bank. But if there is code secretly placed on the site's payment page, the same information quietly goes to an attacker too. This is called web skimming or Magecart, and it is one of the most common and insidious e commerce attacks of recent years. Its insidiousness is this: everything looks normal, the payment goes through, no one notices a problem. This article explains this threat and how to protect against it, for both site owners and shoppers.
How it works
The attacker first gets into the e commerce site somehow; this is usually through outdated e commerce software, a weak admin password or a compromised plugin. Once inside, they add a small, hidden JavaScript code to the payment page. This code captures the customer's card number, expiry date and security code as they type them, and sends them to the attacker's server. The payment still completes normally, because the code does not block payment, it only copies the information. This is why the attack can last for months undetected.
A common variant is that the attack comes not directly to the site but through a third party script the site uses; an analytics tool, a chat widget or an ad script is compromised, and all sites using that script are affected. This is a form of supply chain attack.
Protection for site owners
| Measure | What it does |
|---|---|
| Audit third party scripts | Closes the most common entry path |
| Content security policy (CSP) | Blocks unauthorized scripts from running |
| E commerce software and plugins up to date | Closes known flaws |
| File integrity monitoring | Catches code changes early |
| 2FA on admin access | Makes panel takeover harder |
| Regular security scans | Detects embedded code |
The shared goal of these measures is to ensure that no code you do not know about runs on the payment page. The payment page is the most sensitive point of a site and the place that must be most tightly protected.
Why it is hard to notice
The most dangerous aspect of web skimming is that it leaves no visible sign. The site works, payments succeed, customers get their products. Detection usually comes much later, when complaints arrive from customers whose cards were stolen, or a security researcher finds the code. So protection must rest on prevention and regular monitoring, not on post incident reaction. A regular penetration test and security assessment on an e commerce site can uncover such embedded code.
The legal and reputation dimension
The theft of customer card details on an e commerce site is both a serious reputation crisis and a legal liability. For organizations that process card data, standards like PCI DSS define mandatory security controls; with the personal data dimension, data protection obligations also come into play. When such a breach happens, it is necessary to handle the incident within the 72 hour breach notification framework and run an incident response process.
For shoppers
As a shopper you cannot see this attack directly, but you can reduce the risk. Use a one time virtual card or a low limit card if possible; check your card statement regularly and watch even small unfamiliar transactions, because stolen cards are first tested with small test transactions. When you see a suspicious transaction, contact your bank; for the steps, see the I was defrauded online, what to do guide.
The KAOS and DSET approach
DSET assesses the security of e commerce and payment infrastructures. Our local AI engine KAOS scans and detects third party scripts on a website's payment page, outdated components and suspicious code injections, and reports every finding with a working proof, without false positives. The goal is to catch the hidden code on the payment page before a customer's card details are stolen.
Frequently asked questions
My site works normally, can there still be skimming? Unfortunately yes, and this is the most dangerous aspect of the attack. Web skimming code does not block payment, it only copies the information; so the site keeps working normally and there is no visible sign. Detection usually comes much later. This is why regular security scanning and monitoring are far more important than trusting the feeling that everything looks fine.
Why is CSP so important on the payment page? A content security policy (CSP) tells the browser that only scripts from sources you allow may run. So even if an attacker adds unauthorized code to the payment page, the browser does not run it. Because the payment page is the most sensitive part of a site, this protection is especially valuable there.
How do I protect myself as a shopper? The most effective method is to use a one time virtual card or a low limit card for payments; that way even if your card details are stolen, the damage stays limited. Also check your card statement regularly; stolen cards are first tested with small transactions, so even unfamiliar small amounts can be a warning.
Sources
- PCI Security Standards Council: https://www.pcisecuritystandards.org
- OWASP web security guides: https://owasp.org
- DSET Cyber Security and E commerce Assessment Services: https://dset.com.tr/hizmetler
To assess the security of your e commerce site and payment infrastructure, contact DSET. We provide web security consulting from our Ankara Hacettepe Teknokent laboratory.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.