ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Web-skimming on the rise

Rui Ribeiro at Jscrambler asks why web-skimming attacks are so successful and provides advice on defeating them

 

Criminal gangs are always on the lookout for ways to reach valuable data with minimal effort. A well-known technique for credit card information theft from online shoppers is web-skimming or Magecart attacks, in which threat actors corrupt the code running on a company’s payment page to view and steal information.

 

Jscrambler found that there is unprotected JavaScript running on the payment pages of the top EU and US e-commerce websites, which drastically increases the risk of a data skimming attack. Jscrambler analysed that of the 20 highly trafficked e-commerce websites, 60% had more than 10 different vendors on their payment pages, with only one website not allowing the retrieval of data.

 

Jscrambler also found that, on average, 132 scripts are being loaded on payment pages of EU websites.  Amongst these, 97% of the scripts were found to come from the APIs of third-party payment solutions, such as PayPal or VISA/MasterCard. If any of these scripts were to be compromised, it would cause devastating damage to the organisation and its customers. Moreover, the organisation can face critical legal and financial repercussions.

 

The proliferation of digital payments is constantly growing, so web-skimming threats are likely to increase. Yet, organisations are still not making web-skimming threats a priority. 

 

Web-skimming: low on the risk register

Web-skimming has catastrophic consequences, yet businesses often turn a blind eye to these threats. This is often due to the responsibility of safeguarding customers’ data being theoretically scattered across multiple parties.

 

Because e-commerce companies often hire third parties and payment gateways to facilitate customer payments, they believe that the customer’s financial data is the third party’s responsibility, as they run their scripts on the web page and process the payments. The third parties might have too many JavaScripts or corrupt JavaScript running on their page, which might put the company’s data at risk. Hence, this inadvertent perspective does not put the customer as a high priority and is far too risky of a business model to follow.

 

The British Airways case in 2018 is a distinguishable example of the responsibility for safely processing customers’ data lying with the business. The customers were diverted to a fraudulent website from the British Airways website and the information of 500,000 customers was harvested by cyber criminals. The business’s web domain is targeted; hence no third party can play a role in this.

 

Customers put a lot of trust in a brand when they share sensitive information. The crucial responsibility should then fall on the business which started the transaction. However, it can be argued that although third parties are not directly responsible, they share some liability.

 

Since companies seem to be unable to proactively combat these challenges, the Payment Card Industry (PCI) Data Security Standard (DSS), a popular general payment data security standard, has been updated to force their hands. Its latest version, introduced in March 2022, states that organisations must comply with 64 new requirements, including many around web skimming.

 

New requirements to secure financial data

The new requirements in PCI DSS v4.0 will become mandatory after the 31st of March 2025 – until then, they are deemed best practices.

 

Two of the 64 new requirements are focused on preventing and detecting e-commerce skimming attacks:

 

The first requirement - 6.4.3 - is to ensure that all JavaScript included in the payment page is managed actively. The page will require an approval process and justification for each script added to the payment page. This requirement is designed to not only manage all JavaScript present on the payment page but also to minimise the attack surface.

 

In addition, to ensure malicious clips are not placed on the payment page, there is a requirement to validate the script’s integrity.

 

The second new obligation – 11.6.1 - focuses on detecting unauthorised changes to the payment page as they can potentially be a skimming-type attack. This also requires that an alert is generated when such changes are detected to limit the impact of an attack.

 

Controlling web-skimming attacks

Businesses looking to prepare for the new regulation, or those that already recognise web skimming as a threat, face several security challenges. One of the most significant issues is that the user codes are complicated to secure, as JavaScript is exceptionally dynamic. The JavaScript code from the client side can change depending on the user’s location, operating system, device and browsing behaviour.

 

This means that if two users, for instance, are accessing the same webpage simultaneously from different locations, the JavaScript code being run on their devices would be completely different. This prevents businesses from implementing their usual proactive security procedures, such as screening third-party vendors and auditing codes, as too many variables keep changing.

 

To secure such a dynamic program, the businesses would have to audit every script for every user, daily - which cannot be done manually.

 

Overcoming these challenges requires an automated approach that can keep up with the dynamic nature of JavaScript. Webpage Integrity (WPI) tools are particularly effective as they automatically provide real-time monitoring for every use session and can sandbox third party elements to detect and stop misuse.

 

The greatest challenge in many cases however is getting web skimming on the security agenda in the first place. Despite staggering evidence of web-skimming attacks and examples of high-level disruptions, businesses are not considering the solutions to combat these attacks as they are not recognised as a risk.

 

Organisations must understand that prioritising customer-side security is as vital as internal network security. It is imperative for companies to recognise the impact of web-skimming attacks and take the necessary steps to mitigate these attacks.

 

By understanding these attacks, organisations can then make informed decisions to keep themselves secure.

 


 

Rui Ribeiro is CEO and Cofounder of Jscrambler

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543