> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
MAGECART
/actor/magecart/ · 0 intel reports
Magecart is not a single threat actor but rather an umbrella designation for over a dozen distinct cybercriminal groups that share a common attack methodology: injecting malicious JavaScript code ("skimmers") into the checkout pages of e-commerce websites to silently capture payment card details entered by customers in real time. The stolen payment card data is then exfiltrated to attacker-controlled servers for sale on dark web carding forums or direct fraudulent use.
The Magecart skimming technique is elegant in its simplicity and devastating in its scale: a single successful injection into a widely-used e-commerce platform, payment processing library, or third-party analytics script can compromise the payment data of every customer who completes a purchase on thousands of websites simultaneously, without any visible indication to the customer or merchant. This supply chain approach to web skimming dramatically multiplies the return on each successful compromise.
High-profile Magecart attacks include the 2018 breach of British Airways (affecting 500,000 customers), Ticketmaster UK (compromised via a third-party chatbot supplier), Newegg, and numerous other major retailers. In the British Airways case, the skimming code was active for approximately two weeks before discovery, capturing complete payment card details and personal information of hundreds of thousands of customers making bookings on ba.com.
The Magecart ecosystem has evolved continuously, with individual groups specialising in different techniques , from targeting third-party JavaScript libraries to compromising content delivery networks and website builder platforms to achieve maximum reach. Modern Magecart operations demonstrate sophisticated obfuscation techniques, using encoded scripts and legitimate-appearing code structures to evade detection by both merchants and security scanning tools.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Magecart requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.