Your checkout page looks perfectly normal. Your customers enter their card details, complete their purchases, and receive confirmation emails. But in the background, a few lines of malicious JavaScript are copying every keystroke and sending it to criminals halfway around the world.
Web skimming attacks are among the most insidious threats facing eCommerce merchants because they’re invisible to everyone involved until the chargebacks start rolling in. However, if you know how these attacks work, and understand the real-world damage they cause, you can take the necessary actions to detect, prevent, and recover from them.
What Is a Web Skimming Attack?
Web skimming attacks happen when cybercriminals inject malicious JavaScript into eCommerce checkout pages to steal customer payment data in real time. You might also hear them called e-skimming, formjacking, or Magecart attacks. The theft occurs directly in the customer’s browser, which makes it invisible to both the shopper and the merchant.
Here’s what makes web skimming particularly dangerous: your checkout page looks and functions exactly as it always has. Customers enter their card details without any warning signs. Meanwhile, a hidden script copies every keystroke and sends it to servers controlled by attackers.
- Invisible to shoppers: The checkout experience appears unchanged while data gets captured in the background
- Targets payment forms: Skimmers harvest credit card numbers, CVVs, expiration dates, and billing addresses
- Lives on your legitimate site: Unlike phishing, the attack operates directly on your actual website
Magecart attacks surged 103% in just six months during 2024-2025, making it one of the fastest-growing threats to online commerce.This means credit card fraud prevention can’t be a one-time setup. Instead, it requires ongoing monitoring of checkout pages and payment scripts.
How Online Web Skimming Attacks Work
The attack follows a predictable sequence. A typical web skimming attack unfolds in three stages: attackers first gain access to your site’s code, then inject the malicious script into your checkout page, and finally exfiltrate stolen card data to servers they control. Once you understand each of the following stages, the prevention strategies become clearer.
1. Gaining access to the target website
Attackers look for the path of least resistance. Outdated content management systems like older versions of Magento or WooCommerce often contain known vulnerabilities that haven’t been patched. Weak admin credentials, especially default passwords or credentials reused from other breaches, provide another easy entry point. Compromised hosting environments and insecure FTP (File Transfer Protocol) access round out the most common attack vectors.
2. Injecting malicious skimmer code
Once inside, attackers insert JavaScript code into your checkout pages. The code is typically just a few lines, heavily obfuscated to avoid detection by security scans. It blends in with legitimate scripts, often mimicking the naming conventions of popular analytics or payment libraries.
Some attackers modify existing JavaScript files. Others add entirely new script references that load from external domains designed to look trustworthy.
3. Capturing payment and personal data at checkout
When a customer fills out your payment form, the skimmer activates. It copies form field data in real time, before encryption occurs, capturing everything the customer types. That includes card numbers, CVVs, names, billing addresses, and sometimes login credentials if account creation happens during checkout. The customer completes their purchase normally. They receive their order confirmation. Nothing seems wrong.
4. Exfiltrating stolen data to attacker servers
The captured data gets sent to external servers controlled by the attackers. These command-and-control servers often use domain names that mimic legitimate services, think “google-analytics-cdn.com” or “stripe-verify.net,” to avoid raising suspicion in network logs. The data is typically encrypted during transmission, which ironically helps it bypass security filters designed to detect sensitive information leaving your network.
5. Selling or reusing the stolen card data
Stolen credentials end up on dark web marketplaces or get used directly for fraudulent purchases. Either way, the downstream impact eventually circles back to merchants in the form of chargebacks, fraud liability, and damaged customer trust.
What Are the Types of Web Skimming Attacks?
Not all skimming attacks work the same way. The variations help explain which defenses matter most for your specific setup. Attackers might inject a script directly into your site’s code, or compromise a third-party vendor whose script your checkout already trusts. They might even hijack a payment iframe to display a convincing fake form, so knowing which method you’re up against shapes where you should focus your credit card fraud defenses first.
1. Client-side JavaScript skimming
This is the most common type. The malicious code runs entirely in the customer’s browser, intercepting data as it’s entered into forms. Because it operates client-side, traditional server-side security tools often miss it completely.
2. Server-side skimming
Here, attackers install malicious code directly on your web server. The skimmer captures data before it even reaches the customer’s browser. This approach is harder to detect because it doesn’t appear in browser-side scans or client-side monitoring tools.
3. Supply chain and third-party script skimming
Instead of attacking your site directly, criminals compromise a trusted third-party vendor, like a chat widget provider, an analytics service, or a payment library. When that vendor’s script loads on your checkout page, it brings the skimmer along with it. This is particularly dangerous because you’re trusting code you didn’t write and may not be monitoring closely.
4. Formjacking and Magecart-style attacks
Formjacking describes the specific technique of hijacking web forms. Magecart refers to a loose collective of cybercriminal groups known for large-scale skimming campaigns against major retailers. Both terms are often used interchangeably with web skimming, though they technically describe specific variants.
What Are the Real-World Examples of Web Skimming Attacks?
Online web skimming attacks aren’t theoretical risks. Major brands have suffered significant breaches. These specific numbers make the risk concrete, and the incidents below show exactly how that damage plays out in practice.
1. British Airways Magecart breach
Attackers injected skimmer code into the British Airways payment page, capturing customer card data over several weeks in 2018. The breach affected approximately 380,000 transactions and resulted in a £20 million regulatory fine under GDPR. The scale of that penalty made clear that regulators now treat web skimming failures as a serious compliance issue, not just a technical incident.
2. Ticketmaster third-party script breach
Criminals compromised Inbenta, a chatbot vendor whose code ran on Ticketmaster’s payment pages. The breach spread to Ticketmaster and other clients using the same script, demonstrating how supply chain attacks scale rapidly. It’s a clear reminder that trusting a third-party vendor means trusting every line of code they push to your checkout page, whether you’ve reviewed it or not.
3. Newegg checkout skimmer
Skimmer code inserted into the electronics retailer’s checkout page went undetected for over a month, capturing payment details from customers purchasing computer hardware and electronics. The attack was linked to the FIN6 group, a financially motivated threat actor known for pivoting from point-of-sale malware to web skimming as a lucrative source of stolen card data.
What Data Attackers Steal Through Web Skimming
Skimmers aren’t picky about what they steal. Once malicious code is running on a checkout page, it can capture everything a customer types, not just the payment details needed to complete a purchase. Skimmers target any data entered into compromised forms:
- Credit and debit card numbers, expiration dates, and CVVs
- Cardholder names and billing addresses
- Email addresses and phone numbers
- Login credentials if checkout includes account creation
- Shipping addresses and any other form field data on compromised pages
This broad reach is what makes web skimming so damaging. A single compromised page can hand attackers everything they need for card fraud, identity theft, and account takeover in one shot. This turns one breach into multiple avenues of harm for affected customers.
What Is the Business Impact of Web Skimming on eCommerce Merchants?
The consequences extend far beyond the immediate data theft. What starts as a hidden script on a checkout page can quickly cascade into a much larger business crisis. It touches everything from your bottom line to your legal standing and customer relationships.
- Financial losses: Fraud liability, refunds, and chargeback fees add up quickly
- Regulatory penalties: PCI DSS non-compliance fines and GDPR violations can reach millions
- Reputational damage: Loss of customer trust often outlasts the technical remediation
- Operational disruption: Incident response, forensic investigation, and potential site downtime consume resources
Taken together, these impacts show why web skimming demands a proactive defense strategy rather than a reactive one. The cost of web skimming protection and prevention is almost always lower than the cost of cleanup.
Don't Let Your Checkout Page Become the Next Cautionary Tale
Web skimming attacks succeed precisely because they’re designed to be undetectable, silently siphoning payment data while your checkout page looks and functions exactly as it should. As Magecart campaigns grow more sophisticated and harder to trace, waiting until a breach surfaces is no longer a viable strategy. The businesses that stay protected are the ones that treat checkout security as an ongoing discipline.
Frequently Asked Questions
What is the difference between web skimming and phishing?
Web skimming injects malicious code into a legitimate website to steal data during real transactions. Phishing tricks users into entering information on a fake site controlled by attackers. The key difference: skimming happens on your actual checkout page.
Is web skimming the same as Magecart or formjacking?
Magecart refers to a group of threat actors known for web skimming attacks. Formjacking describes the technique of hijacking web forms. Both fall under the broader category of web skimming.
Do card skimmers work if customers tap to pay online?
Online web skimmers capture data entered into payment forms regardless of how the physical card is used elsewhere. Tap-to-pay protections apply to in-person terminals, not eCommerce checkouts.
Charity Amancio
Charity Amancio specializes in SaaS solutions for global eCommerce businesses, including payments and risk management applications. She bridges the gap between technology and merchant needs, offering practical perspectives on the tools shaping eCommerce. Her insights appear regularly in B2B publications covering the digital commerce space.
















