Magecart, Skimmer, web-skimmer—different names for the same technique: injecting malicious code into the payment page of a legitimate store. The buyer sees a familiar payment form, enters card details, submits—and in parallel with the real payment, the data goes to the attacker's server. This has been happening for 10+ years, and the technique is evolving.
How It Works
The attacker gains access to the store's website (via a vulnerability in Magento, OpenCart, WooCommerce, or through a compromised admin account). They add a few lines of JavaScript to the payment page template or to a third-party library configuration. These lines listen to the payment form and, upon submission, send the data to the attacker's address.
The store usually doesn't notice—purchases continue to go through, the page looks normal. Often they only find out when victims (and payment systems) start reporting a series of similar fraud operations.
Signs to Look For
Too many fields. A normal card payment form: number, expiry, CVV, cardholder name. If the page additionally asks for a card PIN, bank password, SSN/passport—it's likely a skimmer.
Strange domain on the form. Often the payment form is embedded via an iframe from the real processor (Stripe, Adyen, PayPal). If in the iframe card (you can check via DevTools—right-click → Inspect) the domain is not stripe.com or adyen.com, but something unfamiliar—a reason to be wary.
Little-known store or long-unupdated. Sites on old CMS versions with outdated plugins are a favorite target. If the online store looks like it's 10 years old and hasn't been updated, the probability of a skimmer is higher.
What to Do to Avoid Getting Caught
Use a virtual card with a limited balance. If the virtual card data is stolen, it can be quickly blocked and losses are limited to what was on it. Giving a standard bank card with a high limit to random online stores is a bad idea in 2026.
Use Apple Pay / Google Pay where available. The real card number is not transmitted when paying through them—instead, a one-time token is sent. A skimmer won't intercept anything useful.
3DS confirmation. If your bank always requests 3DS for online payments—even stolen card data is useless to the attacker. Enable 3DS in your card settings.
Suspicious behavior—exit and pay differently. If the payment form looks off, there are redirects, too many questions—refuse to pay, contact the store through official channels.
If You Already Entered Data
Immediately block the card. Check transactions—if suspicious ones have already gone through, demand a chargeback through the bank. The faster the block, the smaller the loss: attackers try to use the data within the first hours after theft.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.