Increase in Web Skimming Malware

NJCCIC Alert

Original Release Date: 4/17/2020

Summary

The current COVID-19 pandemic has significantly changed consumer shopping habits and increased online shopping, which has led to an increase in attempts of web skimming, the process of stealing customer data – including credit card information – from compromised online stores. Web skimming attempts soared 26 percent between February and March, and this trend is expected to continue in the upcoming months. Skimming attempts were the highest in the US on Mondays, the busiest day of the week for online shopping.

Recommendations

The NJCCIC recommends online merchants keep platforms updated, security vendors track web skimmers and add protection in their products, and users navigate directly to known websites and designate/monitor one credit card for online shopping. For more information, please see the Malwarebytes Labs blog post and the Payment Card Industry Security Standards Council (PCI SSC) publication on card skimming prevention guidance for large organizations.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.