Magecart Attackers Abuse Google Ad Tool to Steal Data
ID: 919de976-f11f-5eba-aa80-daf52a27ea79
STIX ID: report--919de976-f11f-5eba-aa80-daf52a27ea79
Feed Name: Dark Reading
Date Published: 2025-02-10
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Sucuri researchers uncovered an active Magecart campaign where attackers embed obfuscated, Base64-encoded JavaScript payloads inside Google Tag Manager tags on Magento e-commerce sites to skim payment card data; at least six sites were affected and investigators also found an undeployed backdoor. Recommended actions include removing suspicious GTM tags, performing full site scans to remove skimmers and backdoors, and updating and monitoring Magento installations and GTM activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
