logo

Magecart Attackers Abuse Google Ad Tool to Steal Data

ID: 919de976-f11f-5eba-aa80-daf52a27ea79

STIX ID: report--919de976-f11f-5eba-aa80-daf52a27ea79

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-02-10

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Sucuri researchers uncovered an active Magecart campaign where attackers embed obfuscated, Base64-encoded JavaScript payloads inside Google Tag Manager tags on Magento e-commerce sites to skim payment card data; at least six sites were affected and investigators also found an undeployed backdoor. Recommended actions include removing suspicious GTM tags, performing full site scans to remove skimmers and backdoors, and updating and monitoring Magento installations and GTM activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.