Formjacking and PCI 4.0: What it is and why you should care
Blog post from Basis Theory
Formjacking, also called web skimming or a Magecart attack, involves inserting malicious code into legitimate payment pages to silently capture customers’ sensitive information, particularly credit card details, while allowing transactions to proceed normally. Attackers commonly gain access through vulnerabilities such as cross-site scripting or remote code execution, compromised servers or development environments, or third-party supply chain breaches, as illustrated by the 2018 British Airways incident affecting about 380,000 customers. PCI DSS 4.0 introduces requirements intended to address these threats by requiring controls that protect payment-page integrity and detect unauthorized changes, with validation expected during annual assessments beginning in March 2024. Recommended defenses include using independently hosted payment iframes, monitoring code and network traffic for anomalous changes or data transfers, scanning systems and payment pages for vulnerabilities and malicious scripts, rapidly applying patches, and maintaining response processes. The discussion also presents specialized third-party payment service providers as a way for organizations to reduce compliance and security-management effort while using PCI Level 1 infrastructure and adapting to emerging threats.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.