An attack, also called formjacking or a magecart attack, in which an attacker injects malicious code into a website and extracts the data a user enters into an HTML form, most often payment card details, submitting that stolen data to a server the attacker controls. A 2016 report suggested as many as six thousand e-commerce sites may have been compromised by this class of attack; in 2018, British Airways had three hundred eighty thousand card details stolen through it, and a similar attack against Ticketmaster the same year affected forty thousand customers through maliciously injected code on payment pages. Magecart, the best known family of software used to carry out these attacks, has been deployed by multiple hacking groups both in targeted intrusions, such as one against the retailer Newegg, and through compromises of shared tools like the Shopper Approved e-commerce toolkit, used on hundreds of sites, and the conspiracy site InfoWars. To avoid detection, Magecart software has been found checking for software renderers associated with virtual machines before activating, on the theory that a virtual machine indicates security research rather than a real purchase, and in one October 2023 case a Magecart variant was found hidden inside a compromised site's own 404 error pages, capturing card data entered into an order form before displaying a fake session timeout message to the victim.
Facts
Elements of OffenseInjection of malicious code into a website to extract data a user enters into an HTML form, most often payment card details 1 Notable ExampleBritish Airways 2018 breach, 380,000 card details stolen 1 Classification
Offense GradeMinor or Summary Offense 1 Connections
Has Offense Grade
Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.
Sources
1. Web skimming (Wikipedia)
Lead section
an attack in which the attacker injects malicious code into a website and extracts data from an HTML form that the user has filled in
Prevalence
In 2018, British Airways had 380,000 card details stolen via this class of attack.
View the SourceReader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.