Magecart and card skimming: how to protect your checkout
How Magecart-style skimmers steal card data from checkout pages, how to detect them, and the controls that stop them — including PCI DSS 4.0 script requirements.
How Magecart-style skimmers steal card data from checkout pages, how to detect them, and the controls that stop them — including PCI DSS 4.0 script requirements.
How skimming works
Attackers inject malicious JavaScript into checkout — directly on your server or via a compromised third-party script. The script silently sends card details to the attacker while the order completes normally.
RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Harden your Magento storeSecurity audits, patching and PCI-DSS 4.0 script controls.Get a free security audit →Warning signs
- Customers reporting fraud after buying from you
- Unknown scripts or domains loading on checkout
- Unexpected file changes
- New admin users you don’t recognise
- Alerts from your payment provider
Defences
- Keep Magento / Adobe Commerce fully patched
- Content Security Policy restricting script sources
- Subresource Integrity for third-party scripts
- File integrity and script change monitoring
- Admin 2FA and restricted admin URL
- Hosted payment fields where possible
Common mistakes to avoid
How we help with security
Frequently asked questions
Am I protected if I use a hosted payment page?
It reduces risk, but skimmers can still target pages before the redirect or fake payment forms.
What should I do if I find a skimmer?
Contact your payment provider, remove the code, patch the entry point and investigate — see Malware Removal.
Does PCI DSS 4.0 cover this?
Yes — requirements 6.4.3 and 11.6.1 address payment page scripts.