Throughout 2025, Source Defense Research tracked an evolution in eSkimming sophistication. Attacks are getting harder to spot and easier to scale, adversaries are evolving rapidly and launching campaigns designed to evade common controls and blend into normal web traffic.
Recommended for security, IT, GRC, and eCommerce teams responsible for payment security, fraud prevention , PCI DSS Compliance and third-party script risk.
As a PCI Participating Organization and the pioneer in eSkimming security, Source Defense played a role in the development of new requirements for web security found in PCI DSS 4.0.
We’ve helped thousands of the world’s leading brands address these issues. We’ve also been educating merchants, QSAs, PSPs, eCommerce Platform providers and virtually every stakeholder in PCI compliance on the vulnerabilities in modern website design that make eSkimming attacks possible. We’ve made it our misison to provide guidance around ambiguity in the standard; advise on the pros and cons of approaches provided by the council and we recently launched a free assessment, monitoring and management solution for both merchants and their QSAs.