• Latest

How Online Web Skimming Attacks Work

July 30, 2019 - Updated On July 9, 2026
Inside eCommerce Fraud Trends 2026: What Every Merchant Needs to See Coming

Inside eCommerce Fraud Trends 2026: What Every Merchant Needs to See Coming

July 23, 2026
Hand using a laptop trackpad with a fake phishing email displayed on screen, claiming a credit card is locked and prompting the user to click a 'Re-activate my card' button.

How to Spot a Phishing Scam: 5 Common Signs to Watch Out For

July 21, 2026
A gold envelope with a fishing hook piercing through it, pulling out a slip of paper labeled "password," alongside a phishing icon of an envelope with a hook and the word "Phishing."

Phishing Scams Explained: Types, Examples, and Prevention

July 17, 2026
Fraud analyst using a magnifying glass to review financial charts and transaction data on a desk with a laptop and stock reports.

What Is a Fraud Analyst? An Inside Look at the Role and Its Value

July 15, 2026
Close-up shot of multiple credit cards scattered over a black laptop keyboard. A prominent gold credit card sits in the foreground. Layered on top of the left side is a bright cyan line icon showing a rising bar graph with a percentage sign and an upward-pointing arrow, symbolizing an increase in rates or credit card fraud statistics.

10 Credit Card Fraud Statistics You Can’t Afford to Ignore

July 13, 2026
A Complete Guide to Credit Card Fraud

A Complete Guide to Credit Card Fraud

July 9, 2026
The Merchant’s Guide to eCommerce Fraud Detection

The Merchant’s Guide to eCommerce Fraud Detection

July 8, 2026
Common Dropshipping Supplier Red Flags Every Store Owner Must Know

Common Dropshipping Supplier Red Flags Every Store Owner Must Know

July 3, 2026
8 Dropshipping Scams Targeting Sellers and Buyers in 2026

8 Dropshipping Scams Targeting Sellers and Buyers in 2026

July 2, 2026
How Credit Card Fraud Happens: 10 Common Methods Explained

How Credit Card Fraud Happens: 10 Common Methods Explained

June 25, 2026
Master the basics of Fraud-as-a-Service (FaaS). Discover how this underground economy works and get actionable strategies to defend your business.

A Guide to Fraud-as-a-Service: The New Frontier in Cybercrime

June 23, 2026
What Is a High-Risk Transaction?

What Is a High-Risk Transaction?

June 22, 2026
  • Contribute
  • Contact Us
  • About
  • Join Us
  • Advertise
Sunday, August 2, 2026
Merchant Fraud Journal
ADVERTISEMENT
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
Merchant Fraud Journal
No Result
View All Result

How Online Web Skimming Attacks Work

by Charity Amancio
July 9, 2026

Your checkout page looks perfectly normal. Your customers enter their card details, complete their purchases, and receive confirmation emails. But in the background, a few lines of malicious JavaScript are copying every keystroke and sending it to criminals halfway around the world.

Web skimming attacks are among the most insidious threats facing eCommerce merchants because they’re invisible to everyone involved until the chargebacks start rolling in. However, if you know how these attacks work, and understand the real-world damage they cause, you can take the necessary actions to detect, prevent, and recover from them.

What Is a Web Skimming Attack?

Web skimming attacks happen when cybercriminals inject malicious JavaScript into eCommerce checkout pages to steal customer payment data in real time. You might also hear them called e-skimming, formjacking, or Magecart attacks. The theft occurs directly in the customer’s browser, which makes it invisible to both the shopper and the merchant.

Here’s what makes web skimming particularly dangerous: your checkout page looks and functions exactly as it always has. Customers enter their card details without any warning signs. Meanwhile, a hidden script copies every keystroke and sends it to servers controlled by attackers.

  • Invisible to shoppers: The checkout experience appears unchanged while data gets captured in the background
  • Targets payment forms: Skimmers harvest credit card numbers, CVVs, expiration dates, and billing addresses
  • Lives on your legitimate site: Unlike phishing, the attack operates directly on your actual website

Magecart attacks surged 103% in just six months during 2024-2025, making it one of the fastest-growing threats to online commerce.This means credit card fraud prevention can’t be a one-time setup. Instead, it requires ongoing monitoring of checkout pages and payment scripts.

How Online Web Skimming Attacks Work

The attack follows a predictable sequence. A typical web skimming attack unfolds in three stages: attackers first gain access to your site’s code, then inject the malicious script into your checkout page, and finally exfiltrate stolen card data to servers they control. Once you understand each of the following stages, the prevention strategies become clearer.

Diagram titled 'How Online Web Skimming Attacks Work' by Merchant Fraud Journal, outlining five stages: gaining access to the target website, injecting malicious skimmer code, capturing payment and personal data at checkout, exfiltrating stolen data to attacker servers, and selling or reusing the stolen card data.

1. Gaining access to the target website

Attackers look for the path of least resistance. Outdated content management systems like older versions of Magento or WooCommerce often contain known vulnerabilities that haven’t been patched. Weak admin credentials, especially default passwords or credentials reused from other breaches, provide another easy entry point. Compromised hosting environments and insecure FTP (File Transfer Protocol) access round out the most common attack vectors.

2. Injecting malicious skimmer code

Once inside, attackers insert JavaScript code into your checkout pages. The code is typically just a few lines, heavily obfuscated to avoid detection by security scans. It blends in with legitimate scripts, often mimicking the naming conventions of popular analytics or payment libraries.

Some attackers modify existing JavaScript files. Others add entirely new script references that load from external domains designed to look trustworthy.

3. Capturing payment and personal data at checkout

When a customer fills out your payment form, the skimmer activates. It copies form field data in real time, before encryption occurs, capturing everything the customer types. That includes card numbers, CVVs, names, billing addresses, and sometimes login credentials if account creation happens during checkout. The customer completes their purchase normally. They receive their order confirmation. Nothing seems wrong.

4. Exfiltrating stolen data to attacker servers

The captured data gets sent to external servers controlled by the attackers. These command-and-control servers often use domain names that mimic legitimate services, think “google-analytics-cdn.com” or “stripe-verify.net,” to avoid raising suspicion in network logs. The data is typically encrypted during transmission, which ironically helps it bypass security filters designed to detect sensitive information leaving your network.

5. Selling or reusing the stolen card data

Stolen credentials end up on dark web marketplaces or get used directly for fraudulent purchases. Either way, the downstream impact eventually circles back to merchants in the form of chargebacks, fraud liability, and damaged customer trust.

What Are the Types of Web Skimming Attacks?

Not all skimming attacks work the same way. The variations help explain which defenses matter most for your specific setup. Attackers might inject a script directly into your site’s code, or compromise a third-party vendor whose script your checkout already trusts. They might even hijack a payment iframe to display a convincing fake form, so knowing which method you’re up against shapes where you should focus your credit card fraud defenses first.

1. Client-side JavaScript skimming

This is the most common type. The malicious code runs entirely in the customer’s browser, intercepting data as it’s entered into forms. Because it operates client-side, traditional server-side security tools often miss it completely.

2. Server-side skimming

Here, attackers install malicious code directly on your web server. The skimmer captures data before it even reaches the customer’s browser. This approach is harder to detect because it doesn’t appear in browser-side scans or client-side monitoring tools.

3. Supply chain and third-party script skimming

Instead of attacking your site directly, criminals compromise a trusted third-party vendor, like a chat widget provider, an analytics service, or a payment library. When that vendor’s script loads on your checkout page, it brings the skimmer along with it. This is particularly dangerous because you’re trusting code you didn’t write and may not be monitoring closely.

4. Formjacking and Magecart-style attacks

Formjacking describes the specific technique of hijacking web forms. Magecart refers to a loose collective of cybercriminal groups known for large-scale skimming campaigns against major retailers. Both terms are often used interchangeably with web skimming, though they technically describe specific variants.

What Are the Real-World Examples of Web Skimming Attacks?

Online web skimming attacks aren’t theoretical risks. Major brands have suffered significant breaches. These specific numbers make the risk concrete, and the incidents below show exactly how that damage plays out in practice.

1. British Airways Magecart breach

Attackers injected skimmer code into the British Airways payment page, capturing customer card data over several weeks in 2018. The breach affected approximately 380,000 transactions and resulted in a £20 million regulatory fine under GDPR. The scale of that penalty made clear that regulators now treat web skimming failures as a serious compliance issue, not just a technical incident.

2. Ticketmaster third-party script breach

Criminals compromised Inbenta, a chatbot vendor whose code ran on Ticketmaster’s payment pages. The breach spread to Ticketmaster and other clients using the same script, demonstrating how supply chain attacks scale rapidly. It’s a clear reminder that trusting a third-party vendor means trusting every line of code they push to your checkout page, whether you’ve reviewed it or not.

3. Newegg checkout skimmer

Skimmer code inserted into the electronics retailer’s checkout page went undetected for over a month, capturing payment details from customers purchasing computer hardware and electronics. The attack was linked to the FIN6 group, a financially motivated threat actor known for pivoting from point-of-sale malware to web skimming as a lucrative source of stolen card data.

What Data Attackers Steal Through Web Skimming

Skimmers aren’t picky about what they steal. Once malicious code is running on a checkout page, it can capture everything a customer types, not just the payment details needed to complete a purchase. Skimmers target any data entered into compromised forms:

  • Credit and debit card numbers, expiration dates, and CVVs
  • Cardholder names and billing addresses
  • Email addresses and phone numbers
  • Login credentials if checkout includes account creation
  • Shipping addresses and any other form field data on compromised pages

This broad reach is what makes web skimming so damaging. A single compromised page can hand attackers everything they need for card fraud, identity theft, and account takeover in one shot. This turns one breach into multiple avenues of harm for affected customers.

What Is the Business Impact of Web Skimming on eCommerce Merchants?

The consequences extend far beyond the immediate data theft. What starts as a hidden script on a checkout page can quickly cascade into a much larger business crisis. It touches everything from your bottom line to your legal standing and customer relationships.

  • Financial losses: Fraud liability, refunds, and chargeback fees add up quickly
  • Regulatory penalties: PCI DSS non-compliance fines and GDPR violations can reach millions
  • Reputational damage: Loss of customer trust often outlasts the technical remediation
  • Operational disruption: Incident response, forensic investigation, and potential site downtime consume resources

Taken together, these impacts show why web skimming demands a proactive defense strategy rather than a reactive one. The cost of web skimming protection and prevention is almost always lower than the cost of cleanup.

Don't Let Your Checkout Page Become the Next Cautionary Tale

Web skimming attacks succeed precisely because they’re designed to be undetectable, silently siphoning payment data while your checkout page looks and functions exactly as it should. As Magecart campaigns grow more sophisticated and harder to trace, waiting until a breach surfaces is no longer a viable strategy. The businesses that stay protected are the ones that treat checkout security as an ongoing discipline.

Frequently Asked Questions

What is the difference between web skimming and phishing?

Web skimming injects malicious code into a legitimate website to steal data during real transactions. Phishing tricks users into entering information on a fake site controlled by attackers. The key difference: skimming happens on your actual checkout page.

Is web skimming the same as Magecart or formjacking?

Magecart refers to a group of threat actors known for web skimming attacks. Formjacking describes the technique of hijacking web forms. Both fall under the broader category of web skimming.

Do card skimmers work if customers tap to pay online?

Online web skimmers capture data entered into payment forms regardless of how the physical card is used elsewhere. Tap-to-pay protections apply to in-person terminals, not eCommerce checkouts.

Picture of Charity Amancio

Charity Amancio

Charity Amancio specializes in SaaS solutions for global eCommerce businesses, including payments and risk management applications. She bridges the gap between technology and merchant needs, offering practical perspectives on the tools shaping eCommerce. Her insights appear regularly in B2B publications covering the digital commerce space.

Tags: Online Skimming
TweetShareSend
Previous Post

Fake Google Domains Target Magento Users

Next Post

Capital One Data Breach Hits 100 Million US Customers

Next Post

Capital One Data Breach Hits 100 Million US Customers

Download our latest report:

Our Latest Reports

2024 Fraud Trends Report

2023 Consumer Payments Survey Report

2023 Fraud Trends Report

2022 Chargeback Consumer Survey Report

Fraud Prevention Tactics that Enable Exceptional Customer Experience

Addressing Payment Fraud and The Customer Experience in 2022

2022 Fraud Trends Report

ATO Fraud In Retail Report

2022 Customer Experience Report

3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue

Digital Trust And Safety Report: Combating the Evolving Complexities of Payment Fraud

On-Demand Webinars

New Trends in The Payments Ecosystem

Balancing Customer Experience and Fraud Prevention: What’s the Secret?

Stopping Fraud Across the Customer Lifecycle

Addressing Payment Fraud and the Customer Experience in 2022

 

Get the 2024 Fraud Trends Report

Search Our Site

No Result
View All Result

Our Sponsors

Quick Navigation

  • Home
  • News
  • Join Us
  • About Us
  • Contact Us
  • Advertise
  • Contribute
  • Privacy Policy

The Payments Media Network

Merchant Fraud Journal
Payments Review

Privacy Policy

Our Privacy Policy
Our Terms of Use

Resources

  • Articles
  • eCommerce Fraud Reports
  • eCommerce Fraud Webinars
  • Training and Certifications
  • Jobs Board
  • Associations and Non-Profits
  • Podcasts
  • Vendor Directory

Download the 2023 Fraud Trends Report

No Result
View All Result
  • About Merchant Fraud Journal
    • Interested in Contributing or Guest Posting to Merchant Fraud Journal?
    • Merchant Fraud Journal Editorial Guidelines
  • Advertise on Merchant Fraud Journal
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Contact Us
  • Download Addressing Payment Fraud and Customer Experience Report
  • Download Chargebacks Consumer Survey Report 2022
  • Download Evolving Complexities of Payment Fraud Report
  • Download Fraud Prevention Tactics that Enable Exceptional Customer Experiences Report
  • Download Merchant Fraud Journal 2023 Fraud Trends Report
  • Download Merchant Fraud Journal 2024 Fraud Trends Report
  • Download Merchant Fraud Journal Generative AI Fraud Prevention Checklist for SMBs
  • Download Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
  • Download the 2020 Chargeback and Representment Report
  • Download the 2020 Merchant Fraud Journal Vendor Guide
  • Download the 2021 Fraud Trends Report
  • Download the 2022 Fraud Trends Report
  • Download the 2023 Consumer Payment Trends Report
  • Download the 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue Report
  • Download the MFJ 2022 Customer Experience Report
  • Download the MFJ ATO in Retail Report
  • Home
  • Home Elementor
  • Job Dashboard
  • Join The Merchant Fraud Journal Community
  • Merchant Fraud Journal Advertising Agreement
  • Merchant Fraud Journal Advertising Agreement – Signifyd
  • MFJ Fraud Trends Report Giveaway
  • News
  • Post a Job
  • Privacy Policy
  • Resources
    • #9978 (no title)
    • 2020 Chargeback Representment Guide for Merchants
    • 2020 Vendor Guide
    • 2023 Consumer Payments Survey Report
    • 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue
    • 8 Fraud Prevention Training and Certifications: A 2026 Guide
    • Addressing Payment Fraud and the Customer Experience in 2022
    • Associations and Non-Profits
    • ATO Fraud In Retail Report
    • Balancing Customer Experience and Fraud Prevention: What’s the Secret?
    • Chargebacks Consumer Survey Report 2022
    • Digital Trust & Safety: Combating the Evolving Complexities of Payment Fraud
    • eCommerce Fraud Reports
    • eCommerce Fraud Webinars
    • Fraud Prevention Tactics that Enable Exceptional Customer Experiences
    • How to Build a Recession Proof Chargeback Prevention Strategy
    • How to Reduce Customer Friction During Holiday Sales Season
    • How to Stop Fraud During the 2022 Holiday Season
    • Jobs Board
    • Merchant Fraud Journal 2023 Fraud Trends Report
    • Merchant Fraud Journal’s Fraud Trends 2020 Report
    • Merchant Fraud Journal’s Generative AI Fraud Prevention Report: A Checklist for SMB Companies
    • Merchant Fraud Journal’s Fraud Trends 2021 Report
    • Merchant Fraud Journal’s Fraud Trends 2022 Report
    • MFJ’s 2022 Customer Experience Report
    • Podcasts
    • Prevent High-Velocity Fraud Attacks During the 2021 Holiday Season
    • Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
    • Stopping Fraud Across the Customer Lifecycle
    • The surprisingly easy way to secure your payment data, reduce your risk, and win the war on ecommerce fraud
    • Vendor Directory
    • Webinar – Addressing Payment Fraud and the Customer Experience in 2022
    • Webinar – Mitigating Fraud and Risk on the ACH Network
    • Win January Chargeback Disputes
  • Subscribed
  • Terms and Conditions

© 2021 Payments Media Solutions Canada Inc.

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?