Phishing and scams

AI-assisted card skimmers: the two-step fake checkout trap

Sansec's February investigation into a compromised PrestaShop store shows a fake card form before the real checkout; AI can speed up localisation of deceptive overlays.

Conceptual illustration: AI-assisted card skimmers: the two-step fake checkout trap
Conceptual illustration · SecurCheck

What is confirmed

On 20 February, Sansec documented a skimmer on a large retailer's online store: visitors entered card details in a fake form before being sent to the real payment flow.

Researchers describe reusable skimmer code and explain that generative AI can accelerate fake payment overlays tailored to a store's language and appearance.

What it means

AI can ease lure customisation; the research does not show an autonomous model hacked the shop or generated every observed overlay.

A genuine store can host injected code. HTTPS and historical reputation cannot guarantee an uncompromised checkout.

What to do

If two card forms appear in sequence without a clear reason, stop and contact the merchant through its usual channel.

If you entered details into a suspicious form, contact your bank and monitor charges; merchants should review checkout scripts.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Sansec — enquête technique originale, 20 février 2026