logo

Online shoppers at risk as Magecart skimming hits major payment networks

ID: 922daea7-1345-5cc4-ba1a-6870385fe1db

STIX ID: report--922daea7-1345-5cc4-ba1a-6870385fe1db

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2026-01-14

Date Updated: 2026-04-28

...
...

A long‑running Magecart web‑skimming campaign active since early 2022 is compromising e‑commerce checkout pages to steal cardholder data for major payment networks (including American Express, Diners Club, Discover, JCB, Mastercard, and UnionPay). The attackers use heavily obfuscated JavaScript, self‑destruct routines, and bulletproof hosting to evade detection and maintain a large network of malicious domains; the report advises mitigations such as virtual/single‑use cards, transaction alerts, strong passwords, and web protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.