logo

Credit card theft campaign abuses Stripe to host stolen payment info

ID: 1767bc55-9c6f-5985-901a-28d2a7b83ee5

STIX ID: report--1767bc55-9c6f-5985-901a-28d2a7b83ee5

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Bill Toulas

...
...

A Magecart campaign was discovered that leverages legitimate Google Tag Manager containers to load a JavaScript card skimmer which collects payment and billing data on Magento/Adobe Commerce checkout pages; stolen data is obfuscated locally and exfiltrated by creating fake customer records in the attacker's Stripe account (with a Firestore-based variant also observed), allowing the attackers to bypass CSP/network filters by abusing trusted domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.