eSkimming Attacks Surge as Threat Actors Adopt Persistent, Evolving Tactics

eSkimming campaigns have evolved far beyond one-time incidents, according to new longitudinal research spanning 550 compromised e-commerce websites across 68 countries.

The findings challenge conventional incident response wisdom that equates discovery with recovery, revealing that persistent client-side attacks have become a systemic challenge for the digital retail ecosystem.

The study tracked previously compromised sites over a 12-month period and uncovered a troubling pattern: 18% of previously infected websites remain actively compromised one year after initial detection.

More critically, 57% of these persistently infected sites no longer host the original skimming malware, indicating threat actors have successfully adapted their attack infrastructure following remediation attempts.

Key Study Findings

Source Defense tracked ~3,600 known victims from a year ago, narrowing to 550 active sites for realistic recovery analysis. They excluded offline ones to focus on operational businesses.

A Borderless Threat: Geographic Analysis (Source: sourcedefense)
A Borderless Threat: Geographic Analysis (Source: sourcedefense)
CategorySites AnalyzedPercentage/Details
Clean45282% – No active skimmers detected
Infected9818% – Active skimming present
Still Infected with New/Evolved Paths56 (of 98)57% – Fresh attacks, not leftovers
Offline (from original pool)~16%Potential red flag for unresolved attacks

This table underscores the gap: nearly 1 in 6 sites never cleans up fully.

Attackers adapt fast. When defenders block third-party scripts, foes embed in first-party JavaScript 12% of campaigns shifted this way. Remediation pushes threats deeper, into core site logic.

Global Reach, Varied Persistence

The threat ignores borders. The U.S. (33% of active sites) and U.K. (9%) dominate the sample, but persistence hits everywhere.

CountryActive Sites SharePersistence Rate
SpainNot specified23% (highest)
GermanyNot specified4% (lowest)
Average18%

Germany’s low rate hints at better controls or discipline. Spain’s high one warns of weak spots. Globally, no region escapes.

16% of attacked sites went offline since discovery. While not proven causal, it signals business risk from lingering exposures.

Traditional tools fail here. WAFs scan servers; CSPs check static code. eSkimming executes client-side at runtime. Cleanups miss pivots.

“Attackers watch and innovate,” the report notes. Block one path, they switch domains or embed deeper. Without browser monitoring, they persist.

Persistent eSkimming Evolves Undetected (Source: sourcedefense)

Source Defense pushes runtime controls: track all scripts, flag risky behaviors like payment form access, block exfiltration in real-time.

The firm touts its browser-based tool for visibility into script actions, even trusted ones. It detects fake forms and prevents data grabs, turning reactive cleanups into proactive defense.

This isn’t just tech failure it’s business peril. Unseen skimmers steal cards, erode trust, and may kill sites. Firms must adopt continuous client-side monitoring.

As Magecart groups evolve, point-in-time fixes invite return visits. True recovery demands browser-level eyes.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories