Tags:
The eCommerce ThreatScape Report for August 2024 showed that the industry is facing a level of attack and compromise that we have not seen in nearly a decade of monitoring eCommerce websites for signs of data compromise.
Here are a few key highlights from the report:
There is a significant change taking place in the way criminals are targeting eCommerce websites - in response to the industry's capability to defend.
A few years ago, Digital Skimmers, like Magecart, were the dominant malware being deployed to steal payment card data from eCommerce sites.
The industry has largely figured out how to detect Magecart attacks, so the criminals have had to adapt to their current multi-stage attack approach.
This is what we are seeing now; infected sites with innocuous Digital Loader malware designed to bring in digital skimmers at the appropriate moment in the check out process.
Most security solutions do not know what Digital Loaders look like, or have limited experience with them, which is why we are detecting such a significant surge in Digital Loaders - we are seeing thousands and thousands of eCommerce sites infected with this cunning malware.
Read the report for more information on the eCommerce ThreatScape in August 2024:
eCommerce ThreatScape - August 2024.pdf
Download PDF • 12.25MB
If you do not have a free ThreatView account to detect this malware, please sign up and get ahead of the problem:
Over the last three months, the digital skimmer landscape has changed noticeably. Based on the latest ThreatView charts, Magento 2 remains the most targeted platform, but the biggest movement is elsewhere: Shopify has risen sharply and now appears to be the second most targeted platform for digital skimmers.
In February 2026, we detected 327 compromised PrestaShop websites running card-harvesting malware loaders or digital skimmer malware. By the beginning of June 2026, that number had risen to 1,068. This is an active, expanding campaign affecting a growing number of merchants.
A practical guide for Magento and Adobe Commerce merchants dealing with PolyShell: what it is, how to detect compromise, how ThreatView helps, and what to do next.