An attack surface that spans the whole chain
The attack surface of a payment chain runs from the merchant's checkout page to the acquirer's and PSP's systems, through APIs, customer accounts, and terminals. Each link draws a different type of attack, and each calls for different countermeasures. The threat map below sorts attacks by the link they target and the method they use.
Magecart: digital skimming
Magecart is the umbrella name for a set of groups that practice e-skimming. They inject a malicious script into a merchant's checkout page and siphon off the card data customers enter, in real time. Neither the customer nor the merchant notices, because the transaction goes through normally. The attack is also often indirect: the code sits in a third-party script (analytics, widget, plugin) that the site loads. In that case, what has been compromised is the merchant's software supply chain.
The script sends the data to a domain the attacker controls, whose name often mimics a legitimate service. Detection relies on monitoring unexpected outbound connections and checking the integrity of the code served to customers. Without those controls, a site can stay infected for months before the merchant notices.
Attacks on cards and accounts
Two families of automated attacks dominate online fraud: those that test card numbers and those that take over accounts. Both rely on industrial-grade tooling and on attempt volumes no human operator could reach.
BIN attacks / card testing (also called enumeration attacks) validate card data in bulk through a flood of micro-transactions or one-cent verifications. The fraudster starts from a known BIN and cycles through combinations of expiration date and CVV. The goal isn't to buy anything, but to sort out the live cards for resale. The merchant is left with the fees, waves of declines, and worsening network ratios.
Account takeover (ATO) is when a third party with stolen credentials gains control of a customer's account. Three vectors dominate. Credential stuffing replays email/password pairs leaked from other sites, and it works because people reuse passwords. Phishing tricks victims into entering their credentials on a fake login page. SIM swapping hijacks the phone number to intercept SMS codes. Once inside the account, the attacker uses the stored payment methods, changes the shipping address, or drains a stored balance.
Bots, spoofing, and ransomware
A large share of hostile traffic is automated, and bots do far more than card testing. They create fake accounts to grab sign-up bonuses, buy up inventory (scalping), scrape prices, or overload services. Telling a bot from a real customer relies on device fingerprinting, invisible challenges, and behavioral analysis. The hard part is doing that without adding friction for real customers.
Spoofing means faking a technical identity, whether a domain, an email address, a caller ID, or an entire website, to exploit the trust it inspires. The SPF, DKIM, and DMARC protocols authenticate the sender of a message and make it harder to spoof an email domain. The most expensive form of spoofing is BEC (business email compromise): an email posing as an executive or a supplier to divert a payment. It is also known as CEO fraud.
Ransomware remains the most destructive threat to organizations. The standard playbook today is double extortion: the attackers encrypt systems and steal data, then threaten to publish it. When a PSP, acquirer, or merchant is knocked offline, payment acceptance stops and a business continuity crisis begins. That is why these scenarios are among those covered by the EU's operational resilience regulation (DORA).
| Threat | Target | Main countermeasures |
|---|---|---|
| Magecart / e-skimming | Payment page | CSP, SRI, PSP iframe, integrity monitoring (PCI 6.4.3 / 11.6.1) |
| Card testing / BIN attack | Payment gateway | Rate limiting, velocity filters, CAPTCHA, 3-D Secure |
| Account takeover | Customer account | MFA, credential stuffing detection, account change alerts, device fingerprinting |
| Bots | Sign-up, cart, promotions | Bot management, invisible challenges, behavioral analysis |
| Spoofing / BEC | People, email, domain | SPF/DKIM/DMARC, staff training, dual approval of payments |
| Ransomware | IT systems | Isolated backups, network segmentation, EDR, business continuity and disaster recovery plan |