SecurCheckCyber Center
Need help
Back to analysis tools
All cyber threats
Malware

Magecart / web skimmer

Payment skimmer, web skimmer

Malicious code injected into an online store to capture card details entered at checkout.

Fiche de sensibilisationPrête à diffuser à vos équipes ou clients

MIGHT YOU BE AFFECTED?

Turn knowledge into action.

How does this work?

A script reads the payment form or replaces it with a fake checkout and sends the data to an attacker-controlled domain.

REAL-WORLD EXAMPLE

« An altered third-party script captures card numbers during an otherwise normal online order. »

Typical sequence

  1. 1Compromise a store or supplier
  2. 2Inject a payment skimmer
  3. 3Capture and exfiltrate card details

Warning signs

  • A new external checkout script
  • Unknown domains contacted during payment
  • Customer complaints after purchases

How to protect yourself

  • Monitor checkout scripts
  • Apply Content Security Policy and script integrity
  • Limit third-party code on payment pages

If you think you are affected

Stop affected payments, preserve evidence and inspect the site and administrator access. Contact your payment provider and follow relevant notification duties.

Get help

Last updated: 6 September 2026