24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//E-Commerce · 2026
E-Commerce · Case 2026

Magento store with 8M TL monthly revenue · Magecart skimmer · 840 cards leaked in 14 days

A Magecart skimmer was added to the checkout.js of a Magento store with 8M TL in monthly revenue 14 days earlier. 840 cards had flowed to a Latvian C2. DSET cleaned it in 4 hours; after the PCI-DSS notification + coordination with banks + a DSET pentest a PCI-DSS Level 1 certificate was obtained, with 18 months of clean operation.

Duration
4 hours of cleanup · 30 days for PCI-DSS certification
Scope
840 leaked cards · 8M TL monthly revenue · 14 days of exposure
Customer Satisfaction
★★★★★

01 The Challenge

A customer complained: "my card details were leaked." checkout.js git diff: 12 lines of JavaScript added 14 days earlier. The Magento admin password had been changed 14 days earlier from "admin123" to "Admin2024!" (still weak). The skimmer payload base64-encoded the form fields and POSTed them to latvia-c2[.]xyz/api. Visa Fraud Detection confirmed 47 frauds.

02 DSET's Approach

01

T+0 · Immediate cleanup

The skimmer was removed, all Magento admin passwords reset, MFA enforced, the Cloudflare WAF outbound "latvia-c2.xyz" blocked.

02

T+72h · DSET forensic investigation

Web server access log: attacker IP a Latvian VPN, a CVE-2024-34102 (Magento XXE→RCE) exploit pattern. 840 cards leaked (14 days × 60/day).

03

T+1 week · PCI-DSS notification

Mandatory PCI-DSS Level 1 notification. SMS + e-mail to 840 customers. Banks started card cancellation processes (Visa fraud reimbursement 85%).

04

T+2 weeks · Magento clean install

Latest Magento 2.4.7-p3 + all extensions up to date. WAF (Cloudflare Pro) strict rules + DDoS protection. Monthly dependency scan (Snyk) + daily SAST/DAST.

05

T+30 days · DSET pentest

OWASP ASVS L2 pentest: 5 additional findings (SSRF + IDOR + weak JWT), all patched.

06

T+60 days · PCI-DSS QSA

Qualified Security Assessor audit. A PCI-DSS Level 1 certificate was obtained.

07

T+18 months · Continuously clean

DSET quarterly pentest + 24/7 SOC monitoring. In 18 months 1 vulnerability was caught early; no critical leak.

03 Results in Numbers

4 hours
Skimmer cleanup
85%
Visa fraud reimbursement
Certified
PCI-DSS Level 1
2% (acceptable)
Customer loss
0
PCI-DSS penalty
0
Repeat attack (18 months)

04 Customer Testimonial

"

DSET advised us to file the PCI-DSS notification proactively, and we avoided a 2.4M TL penalty risk. Our brand value was preserved thanks to transparency; it even increased.

E-Commerce Director
Online Store · 8M TL monthly revenue
★★★★★

05 Key Takeaways

The Magento admin password must be protected from weak passwords like "admin123"; a password manager + 2FA is mandatory
If PCI-DSS notifications are filed proactively, the penalty risk drops by 95% and brand value is preserved
WAF + dependency scan + SAST/DAST is three-layer protection; insufficient on its own
A system capable of detecting a Magecart skimmer within 14 days definitely exists; it is simply not being watched (PCI-DSS Level 1 mandatory)

06 Services Used in This Case

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms