Cybercriminals Use Stripe to Steal Bank Card Data

Photo: BleepingComputer
Quick answer
Cybercriminals from the Magecart group have developed a new method to steal bank card data by exploiting Stripe’s payment system API.
Cybercriminal group Magecart has intensified attacks on e-commerce websites using an unconventional method to harvest bank card data. In this new campaign, attackers inject malicious JavaScript code into checkout pages, intercepting payment details entered by users.
The attack’s key feature is its use of Stripe’s payment system API to transmit stolen data. This allows criminals to disguise malicious traffic as legitimate requests, complicating detection by standard security tools. Cybersecurity experts emphasize that this approach undermines the effectiveness of traditional traffic filtering methods.
According to researchers, the attack targets vulnerable websites running outdated CMS versions or plugins. To mitigate such threats, experts recommend regularly updating software, implementing multi-factor authentication for admin panels, and deploying specialized solutions to monitor suspicious activity on websites.
Common questions
- Common questions
- Cybercriminals from the Magecart group have developed a new method to steal bank card data by exploiting Stripe’s payment system API.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml