Tags:
The buzz around the new PCI DSS requirements for eCommerce is well-deserved - and for good reason.
The evolving threat landscape demands that businesses stay ahead, particularly in securing the checkout process (requirement 6.4.3) and monitoring all scripts loaded during that critical stage. This is a significant leap forward in combating the wave of cybercrime targeting eCommerce platforms.
According to our latest eCommerce ThreatScape Report, March 2024 marked a notable shift in malware tactics, moving from digital skimmers to digital loaders.

Why does this matter?
In simple terms, the industry has largely caught up to detecting digital skimmers, prompting cybercriminals to adapt. To stay in business, they’ve developed a two-stage attack: deploying a seemingly harmless digital loader first, which then calls in a digital skimmer from another compromised domain. This innovation has caused a sharp increase in detected digital loaders—an area where our R&D and forensic teams excel in providing robust detection capabilities.
How does PCI DSS Requirement 6.4.3 help?
This requirement will drastically strengthen the defence for eCommerce sites.
Enter File Change Monitoring (Requirement 11.5.2) - a game-changing tool for understanding and responding to changes in your website’s filesystem.
Imagine this scenario:
But is it truly resolved?
Without deeper insights, you’re left wondering:
Unfortunately, many businesses find themselves in a costly game of cat and mouse, with hackers reinfecting sites within hours of cleanup. This is where a forensic-grade File Change Monitoring system becomes indispensable—and cost-effective.
How ThreatView Advanced Edition Helps:
Our solution offers a fully integrated File Change Monitoring system that meets PCI DSS Requirement 11.5.2, providing unparalleled control and insight. Key features include:

This powerful capability empowers your developers and agencies to save time, reduce costs, and effectively counter sophisticated cyberattacks.
With ThreatView Advanced Edition, you gain an out-of-the-box solution that simplifies security operations, supports PCI DSS compliance, and provides peace of mind for your eCommerce operations.
Over the last three months, the digital skimmer landscape has changed noticeably. Based on the latest ThreatView charts, Magento 2 remains the most targeted platform, but the biggest movement is elsewhere: Shopify has risen sharply and now appears to be the second most targeted platform for digital skimmers.
In February 2026, we detected 327 compromised PrestaShop websites running card-harvesting malware loaders or digital skimmer malware. By the beginning of June 2026, that number had risen to 1,068. This is an active, expanding campaign affecting a growing number of merchants.
A practical guide for Magento and Adobe Commerce merchants dealing with PolyShell: what it is, how to detect compromise, how ThreatView helps, and what to do next.