Tags:
Based on the trends identified by ThreatView on the escalation in PrestaShop attacks, the past month has brought a sharp inflection in both skimmer detections and overall malware prevalence on compromised PrestaShop storefronts.
Digital skimmers detected on PrestaShop increased by ~110% month-over-month. That rate of change is notable on its own, but it also reinforces a broader pattern: the attack is not only ongoing, it’s growing.
This jump indicates more than “background noise.” When skimmer activity more than doubles in a month, it typically suggests one (or more) of the following:
Regardless of the mechanism, the result is the same: PrestaShop merchants are experiencing the steepest increase in active skimming risk right now.
Magento 1 skimmer detections increased by ~29% month-over-month.
That growth aligns with the persistent reality of Magento 1: legacy deployments remain attractive targets because they frequently run on older stacks with aging extensions, and are more likely to be under-maintained.
Skimmer counts matter - but they’re only part of the picture. The most important macro indicator is the overall malware footprint on PrestaShop sites.
From October 2025 to July 2026, malware on PrestaShop storefronts grew roughly an 8× increase over that period.
Put simply, the issue is not slowing down.
In practical terms, this kind of compounding growth implies:
If you run PrestaShop - or support clients who do - the key is to treat this as an active, fast-moving campaign rather than an occasional risk.
The market signal is clear: attackers are currently concentrating effort where it scales - and right now that’s PrestaShop. With skimmer detections up ~110% in a month, the trajectory points to continued pressure on merchants unless proactive, defensive action is taken.
Over the last three months, the digital skimmer landscape has changed noticeably. Based on the latest ThreatView charts, Magento 2 remains the most targeted platform, but the biggest movement is elsewhere: Shopify has risen sharply and now appears to be the second most targeted platform for digital skimmers.
In February 2026, we detected 327 compromised PrestaShop websites running card-harvesting malware loaders or digital skimmer malware. By the beginning of June 2026, that number had risen to 1,068. This is an active, expanding campaign affecting a growing number of merchants.
A practical guide for Magento and Adobe Commerce merchants dealing with PolyShell: what it is, how to detect compromise, how ThreatView helps, and what to do next.