eSkimming campaigns have evolved far beyond one-time incidents, according to new longitudinal research spanning 550 compromised e-commerce websites across 68 countries.
The findings challenge conventional incident response wisdom that equates discovery with recovery, revealing that persistent client-side attacks have become a systemic challenge for the digital retail ecosystem.
The study tracked previously compromised sites over a 12-month period and uncovered a troubling pattern: 18% of previously infected websites remain actively compromised one year after initial detection.
More critically, 57% of these persistently infected sites no longer host the original skimming malware, indicating threat actors have successfully adapted their attack infrastructure following remediation attempts.
Key Study Findings
Source Defense tracked ~3,600 known victims from a year ago, narrowing to 550 active sites for realistic recovery analysis. They excluded offline ones to focus on operational businesses.
| Category | Sites Analyzed | Percentage/Details |
|---|---|---|
| Clean | 452 | 82% – No active skimmers detected |
| Infected | 98 | 18% – Active skimming present |
| Still Infected with New/Evolved Paths | 56 (of 98) | 57% – Fresh attacks, not leftovers |
| Offline (from original pool) | ~16% | Potential red flag for unresolved attacks |
This table underscores the gap: nearly 1 in 6 sites never cleans up fully.
Attackers adapt fast. When defenders block third-party scripts, foes embed in first-party JavaScript 12% of campaigns shifted this way. Remediation pushes threats deeper, into core site logic.
Global Reach, Varied Persistence
The threat ignores borders. The U.S. (33% of active sites) and U.K. (9%) dominate the sample, but persistence hits everywhere.
| Country | Active Sites Share | Persistence Rate |
|---|---|---|
| Spain | Not specified | 23% (highest) |
| Germany | Not specified | 4% (lowest) |
| Average | – | 18% |
Germany’s low rate hints at better controls or discipline. Spain’s high one warns of weak spots. Globally, no region escapes.
16% of attacked sites went offline since discovery. While not proven causal, it signals business risk from lingering exposures.
Traditional tools fail here. WAFs scan servers; CSPs check static code. eSkimming executes client-side at runtime. Cleanups miss pivots.
“Attackers watch and innovate,” the report notes. Block one path, they switch domains or embed deeper. Without browser monitoring, they persist.
Source Defense pushes runtime controls: track all scripts, flag risky behaviors like payment form access, block exfiltration in real-time.
The firm touts its browser-based tool for visibility into script actions, even trusted ones. It detects fake forms and prevents data grabs, turning reactive cleanups into proactive defense.
This isn’t just tech failure it’s business peril. Unseen skimmers steal cards, erode trust, and may kill sites. Firms must adopt continuous client-side monitoring.
As Magecart groups evolve, point-in-time fixes invite return visits. True recovery demands browser-level eyes.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
