Magecart, Skimmer, web-skimmer—different names for the same technique: injecting malicious code into the payment page of a legitimate store. The buyer sees a familiar payment form, enters card details, submits—and in parallel with the real payment, the data goes to the attacker's server. This has been happening for 10+ years, and the technique is evolving.

How It Works

The attacker gains access to the store's website (via a vulnerability in Magento, OpenCart, WooCommerce, or through a compromised admin account). They add a few lines of JavaScript to the payment page template or to a third-party library configuration. These lines listen to the payment form and, upon submission, send the data to the attacker's address.

The store usually doesn't notice—purchases continue to go through, the page looks normal. Often they only find out when victims (and payment systems) start reporting a series of similar fraud operations.

Signs to Look For

Too many fields. A normal card payment form: number, expiry, CVV, cardholder name. If the page additionally asks for a card PIN, bank password, SSN/passport—it's likely a skimmer.

Strange domain on the form. Often the payment form is embedded via an iframe from the real processor (Stripe, Adyen, PayPal). If in the iframe card (you can check via DevTools—right-click → Inspect) the domain is not stripe.com or adyen.com, but something unfamiliar—a reason to be wary.

Little-known store or long-unupdated. Sites on old CMS versions with outdated plugins are a favorite target. If the online store looks like it's 10 years old and hasn't been updated, the probability of a skimmer is higher.

What to Do to Avoid Getting Caught

Use a virtual card with a limited balance. If the virtual card data is stolen, it can be quickly blocked and losses are limited to what was on it. Giving a standard bank card with a high limit to random online stores is a bad idea in 2026.

Use Apple Pay / Google Pay where available. The real card number is not transmitted when paying through them—instead, a one-time token is sent. A skimmer won't intercept anything useful.

3DS confirmation. If your bank always requests 3DS for online payments—even stolen card data is useless to the attacker. Enable 3DS in your card settings.

Suspicious behavior—exit and pay differently. If the payment form looks off, there are redirects, too many questions—refuse to pay, contact the store through official channels.

If You Already Entered Data

Immediately block the card. Check transactions—if suspicious ones have already gone through, demand a chargeback through the bank. The faster the block, the smaller the loss: attackers try to use the data within the first hours after theft.

VirtCardPay

A virtual card in 2 minutes

Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.

Open in Telegram Learn more about the service →
This material is for informational purposes only and is not financial advice. Data and service terms may change, so check primary sources before making a payment or investment decision. Mentions of third-party brands and services do not imply official partnership, support, or endorsement by VirtCardPay.
Back