Malware
Magecart / web skimmer
Payment skimmer, web skimmer
Malicious code injected into an online store to capture card details entered at checkout.
Fiche de sensibilisationPrête à diffuser à vos équipes ou clients
MIGHT YOU BE AFFECTED?
Turn knowledge into action.
How does this work?
A script reads the payment form or replaces it with a fake checkout and sends the data to an attacker-controlled domain.
REAL-WORLD EXAMPLE
« An altered third-party script captures card numbers during an otherwise normal online order. »
Typical sequence
- 1Compromise a store or supplier
- 2Inject a payment skimmer
- 3Capture and exfiltrate card details
Warning signs
- A new external checkout script
- Unknown domains contacted during payment
- Customer complaints after purchases
How to protect yourself
- Monitor checkout scripts
- Apply Content Security Policy and script integrity
- Limit third-party code on payment pages
If you think you are affected
Stop affected payments, preserve evidence and inspect the site and administrator access. Contact your payment provider and follow relevant notification duties.
Last updated: 6 September 2026