Reference🔐 Security & dataIntermediate⏱ 12 min read

🎯 Cyber threats to payments

Magecart, BIN attacks and card testing, account takeover, bots, spoofing, and ransomware: a map of the attacks on the payment chain and how to counter them

An attack surface that spans the whole chain

The attack surface of a payment chain runs from the merchant's checkout page to the acquirer's and PSP's systems, through APIs, customer accounts, and terminals. Each link draws a different type of attack, and each calls for different countermeasures. The threat map below sorts attacks by the link they target and the method they use.

Customeraccount, devicePayment pagethe merchant's DOMPSP / gatewayAuthorization APIAcquirerbatch, settlementIssuerACS, decisionnormal flowthe accountthe browserthe APIthe decisionAccount takeovercredential stuffing · phishingMagecart / e-skimmingcompromised third-party scriptCard testingenumeration with micro-amountsAuthorization fraudreplay, MOTO, unqualified MITMFA · device fingerprintCSP · SRI · integrity 11.6.1velocity · rate limit · 3DSqualified MIT · exemptionsoutside the payment chainRansomware · BECIT systems and people, outside the flowisolated backups · EDR · BCP/DRPnormal flowmodus operandicountermeasureOnly one of these five attacks can stop you without going through the payment chain: ransomware.
🕸️
On the page
Magecart / e-skimming: malicious JavaScript steals card data in the customer's browser.
🃏
On the card
Card testing and BIN attacks: mass validation of stolen card numbers through micro-transactions.
🔓
On the account
Account takeover: credential stuffing, phishing, and SIM swaps hijack the customer account.
🤖
Through bots
Automated traffic: scalping, fake account creation, sign-up fraud, and promo abuse.
🎭
Through deception
Spoofing and social engineering: faking a domain, email address, or phone number to fool people and filters.
🔐
On IT systems
Ransomware: encryption and double extortion that cripple PSPs, acquirers, and merchants.

Magecart: digital skimming

Magecart is the umbrella name for a set of groups that practice e-skimming. They inject a malicious script into a merchant's checkout page and siphon off the card data customers enter, in real time. Neither the customer nor the merchant notices, because the transaction goes through normally. The attack is also often indirect: the code sits in a third-party script (analytics, widget, plugin) that the site loads. In that case, what has been compromised is the merchant's software supply chain.

⚠️
Why PCI DSS v4 goes after it
Two PCI DSS v4 requirements target this attack directly. Requirement 6.4.3 calls for managing and authorizing every script on the payment page, and 11.6.1 calls for detecting any tampering with them. Both have been mandatory since March 31, 2025. Typical controls combine CSP, Subresource Integrity, script monitoring, and moving card entry into a PSP-hosted iframe.

The script sends the data to a domain the attacker controls, whose name often mimics a legitimate service. Detection relies on monitoring unexpected outbound connections and checking the integrity of the code served to customers. Without those controls, a site can stay infected for months before the merchant notices.

Attacks on cards and accounts

Two families of automated attacks dominate online fraud: those that test card numbers and those that take over accounts. Both rely on industrial-grade tooling and on attempt volumes no human operator could reach.

BIN attacks / card testing (also called enumeration attacks) validate card data in bulk through a flood of micro-transactions or one-cent verifications. The fraudster starts from a known BIN and cycles through combinations of expiration date and CVV. The goal isn't to buy anything, but to sort out the live cards for resale. The merchant is left with the fees, waves of declines, and worsening network ratios.

Account takeover (ATO) is when a third party with stolen credentials gains control of a customer's account. Three vectors dominate. Credential stuffing replays email/password pairs leaked from other sites, and it works because people reuse passwords. Phishing tricks victims into entering their credentials on a fake login page. SIM swapping hijacks the phone number to intercept SMS codes. Once inside the account, the attacker uses the stored payment methods, changes the shipping address, or drains a stored balance.

$4.88M
global average cost of a data breach in 2024, up 10% year over year
IBM Cost of a Data Breach 2024
Stolen credentials
one of the most common initial vectors in the breaches analyzed
Verizon DBIR 2024
1 cent
typical amount of a card testing transaction
ℹ️
The CVV is no longer enough
Against card testing, a static security code offers little protection: attackers recover it by brute force spread across a large number of attempts. Effective countermeasures combine rate limiting, behavioral detection, velocity filters, and above all strong customer authentication through 3-D Secure on risky transactions.

Bots, spoofing, and ransomware

A large share of hostile traffic is automated, and bots do far more than card testing. They create fake accounts to grab sign-up bonuses, buy up inventory (scalping), scrape prices, or overload services. Telling a bot from a real customer relies on device fingerprinting, invisible challenges, and behavioral analysis. The hard part is doing that without adding friction for real customers.

Spoofing means faking a technical identity, whether a domain, an email address, a caller ID, or an entire website, to exploit the trust it inspires. The SPF, DKIM, and DMARC protocols authenticate the sender of a message and make it harder to spoof an email domain. The most expensive form of spoofing is BEC (business email compromise): an email posing as an executive or a supplier to divert a payment. It is also known as CEO fraud.

Ransomware remains the most destructive threat to organizations. The standard playbook today is double extortion: the attackers encrypt systems and steal data, then threaten to publish it. When a PSP, acquirer, or merchant is knocked offline, payment acceptance stops and a business continuity crisis begins. That is why these scenarios are among those covered by the EU's operational resilience regulation (DORA).

ThreatTargetMain countermeasures
Magecart / e-skimmingPayment pageCSP, SRI, PSP iframe, integrity monitoring (PCI 6.4.3 / 11.6.1)
Card testing / BIN attackPayment gatewayRate limiting, velocity filters, CAPTCHA, 3-D Secure
Account takeoverCustomer accountMFA, credential stuffing detection, account change alerts, device fingerprinting
BotsSign-up, cart, promotionsBot management, invisible challenges, behavioral analysis
Spoofing / BECPeople, email, domainSPF/DKIM/DMARC, staff training, dual approval of payments
RansomwareIT systemsIsolated backups, network segmentation, EDR, business continuity and disaster recovery plan
Threats and countermeasures
🔑
Defense works in layers
No single measure stops all of these attacks, because each one targets a different point in the chain. Defense in depth therefore layers page hardening, strong authentication, behavioral monitoring, offline backups, and crisis drills. People remain the most frequently attacked link, which is why staff training and payment approval procedures play such a large role.