logo

Cyberattacks once again Trap Black Friday Shoppers

ID: b9e8d4a4-8e19-5495-806c-b3009ca107d0

STIX ID: report--b9e8d4a4-8e19-5495-806c-b3009ca107d0

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-09-18

Date Updated: 2026-05-01

...
...

ThreatLabz observed a spike in holiday-targeted e-commerce attacks where attackers injected obfuscated JavaScript skimmers into legitimate shopping sites (Magento and WooCommerce) to capture and exfiltrate payment data during Black Friday/Cyber Monday. The report details multiple cases (including the Grelos skimmer), describes techniques such as cookie storage, altered HTML field IDs, base64-encoded exfiltration, anti-debug checks, and lists observed exfiltration/redirect domains to help defenders identify and block these campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.