Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Ecommerce Card Skimming
Threats, Abuse & Incident Response

Ecommerce Card Skimming

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

Ecommerce card skimming is the theft of payment data from online checkout pages by malicious code inserted into a merchant site. The attacker captures card details as customers submit them, then resells or reuses the information for fraud. This is a common path from website compromise to payment abuse.

How ecommerce card skimming works

Ecommerce card skimming is usually implemented by injecting malicious JavaScript into a checkout flow, then reading payment fields as the customer types or submits them. The theft happens in the browser, inside an otherwise legitimate transaction path, which is why it can remain invisible until fraudulent card use appears later.

The technique is often associated with compromise of the merchant’s site, a third-party script, a content management extension, or another upstream dependency that can modify page content. Even when the payment processor is trusted, the checkout page itself can become the collection point for card data.

Where the theft occurs in the checkout lifecycle

The important detail is that skimming does not require the attacker to defeat payment card networks directly. It only requires access to the browser session or to the code that renders the page. That makes the browser a high-value interception point because payment card number, expiration date, and card verification data may all be exposed before the transaction ever leaves the customer’s device.

In practice, the theft may occur at load time, during keystroke capture, at form submission, or through script that copies the contents of hidden or visible payment fields. The attacker then exfiltrates the data to an external server, where it can be aggregated and monetized.

Why ecommerce card skimming is hard to notice

Skimming blends into normal web activity because the page still functions, the checkout still completes, and the customer often sees no obvious error. A well-placed script can imitate the site’s styling, wait for a real user action, and send data in ways that look like ordinary telemetry or analytics traffic.

That low visibility is what makes the technique durable. Defenders may focus on payment gateway security while missing the integrity of the merchant page, the script supply chain, or the client-side execution path that actually captures the data.

Business and security consequences

The direct consequence is payment-card fraud, but the wider impact can include chargebacks, incident response cost, customer notification, legal exposure, and loss of trust. For merchants, a single compromise can affect any checkout page that reuses the same compromised asset or JavaScript bundle.

Because the attack abuses a legitimate commerce flow, detection often depends on finding unexpected page changes, unusual outbound requests, or code that accesses payment fields without a valid business need. Merchant compromise and malicious script injection are the core failure points.

Risk and Threat Considerations

Ecommerce card skimming creates a high-impact exposure because the attacker steals data at the point of entry, before normal payment controls can limit misuse. A compromised checkout page can collect many cards quickly, and the theft may continue until the injected code is removed.

Failure mechanism: The attacker gains the ability to alter client-side code or a third-party script used by the checkout page, then captures payment details as they are entered or submitted.

Impact: Stolen card data can be sold, replayed for fraud, and used to trigger chargebacks, customer harm, and incident response obligations for the merchant.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while OWASP ASVS, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1056.001 — KeyloggingCovers script-based capture of sensitive user input in the browser.
Recommendation — Detect script-based input capture and review client-side telemetry for unexpected field access.
OWASP ASVSV14 — Data ProtectionApplies because checkout pages must protect payment data in transit and in use on the client side.
Recommendation — Protect payment fields from exposure to untrusted scripts and verify client-side data handling.
NIST SP 800-53 Rev 5SI-7 — Software, Firmware, and Information IntegrityDirectly supports integrity monitoring for web content and injected checkout code.
Recommendation — Monitor checkout assets for unauthorized changes and block untrusted script execution.
CIS Controls v8CIS-16 — Application Software SecurityApplies to securing web applications against malicious code injection and abuse.
Recommendation — Harden web application change control and validate third-party scripts before deployment.

Practitioner Guidance

What to watch for: Treat checkout-page integrity as a primary control surface, not just the payment processor connection. Unexpected script additions, unapproved tag-manager changes, and outbound connections from checkout pages are strong signals that skimming may be present.

Practitioner takeaway: If the browser can see the card data, so can attacker-controlled script, which means client-side integrity must be monitored with the same seriousness as server-side authentication.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org