New payment skimming in web shops hides behind WebRTC
Researchers at Sansec have identified a new form of digital skimming that abuses WebRTC, the browser capability normally used for real-time communication, to evade traditional detection controls. The technique lets malicious code operate outside the visibility of standard security tooling. Unlike conventional Magecart-style attacks, it does not rely on easily detectable scripts embedded in web pages, but uses browser-native capabilities to transmit stolen payment data. That makes it considerably harder to identify through standard inspection.
What this means for your organisation
This hits organisations selling online, and it hits where it hurts most: the payment flow. Because the code usually arrives through a third-party script for analytics, chat or marketing, it is often not your own code that fails. The result is stolen card data, potential claims from card networks, and a customer experience that no apology repairs.
Berigo recommends
- Inventory every third-party script running on your payment pages, and remove those that do not belong there.
- Deploy Content Security Policy and subresource integrity for scripts in the checkout flow.
- Require script vendors on your site to document how they secure their own delivery chain.
- Monitor changes to checkout page scripts, and let any change trigger review.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch