RESOURCES / THREAT RESEARCH

Magento feature abused to bypass payment provider and steal credit cards

Attackers have discovered a clever new way to steal credit card data: by turning one of Magento’s own features against it. They hijacked a trusted part of the eCommerce platform that’s used to refresh customer-specific content – like the shopper’s name, cart summary, and shipping details – during checkout without reloading the page. 

Related Reads

Source Defense

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.