Knowledgebase

Preventing Card Skimming on Checkout Print

  • woocommerceonlinestores, woocommerce, hacked, malware, twofactor, plugins, themes, support, uploads
  • 0

The most damaging compromise a shop can suffer.

WHAT IT IS

JavaScript injected into your checkout page that copies card details as customers type and sends them to an attacker. The order still completes normally, so nothing appears wrong.

It is designed to be invisible and can run for months.

HOW IT GETS THERE

An out-of-date plugin or theme A nulled extension A compromised administrator account A vulnerable file upload

PREVENTION

Use a hosted gateway where card details are entered on the provider's page or in their iframe. If the details never touch your site, there is nothing to skim. Keep everything updated Two-factor authentication on all admin accounts Never use nulled software

DETECTION

Compare checkout page source against a known-good copy periodically Run ImunifyAV over the account Watch for unfamiliar scripts loading on checkout Take customer reports of card fraud seriously. Several customers reporting fraud after buying from you is the clearest signal there is.

IF YOU FIND ONE

Take the shop offline, open a ticket, clean thoroughly, rotate every credential, and tell affected customers.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot