Back to Blog

What Is Formjacking and How It Steals Credit Card Numbers

PB

Patrick Bushe

September 16, 2024 · 5 min read

Formjacking is when attackers sneak malicious code into a website's checkout page. As you type your card number, the code copies it and sends it to the attackers, while your purchase goes through normally. Nothing looks wrong, so victims usually only find out when fraud appears on their statement.

How it works

  1. Attackers find a way to change the site's JavaScript, often through a vulnerable plugin, a hacked admin account or a third-party script the site loads, such as chat or analytics.
  2. They add a small piece of code that watches the payment form.
  3. When you submit, the code sends a copy of the card number, expiry date, security code and address to a server the attackers control.

The groups behind many of these attacks are often called Magecart, after early attacks on Magento stores.

Major cases

  • British Airways, 2018: attackers altered code on the airline's website and app and collected payment details of hundreds of thousands of customers. The UK Information Commissioner's Office fined BA £20 million in 2020.
  • Ticketmaster UK, 2018: a third-party chat tool on its payment pages was compromised, exposing customers' payment data.

How stores defend against it

  • Limit third-party scripts on payment pages.
  • Content Security Policy to control which scripts can run and where data can be sent.
  • Subresource Integrity so scripts are blocked if they've been altered.
  • Hosted payment pages or fields from the payment provider, so card details never touch the store's own page.
  • Monitoring for unexpected script changes. The PCI DSS 4.0 card security standard made script inventory (6.4.3) and change detection (11.6.1) on payment pages mandatory from March 31, 2025.

How to protect yourself

  • Use digital wallets such as Apple Pay, Google Pay or PayPal, which don't share your real card number with the store.
  • Use virtual card numbers if your bank offers them.
  • Prefer credit cards to debit cards online; fraud protection is usually stronger and your bank balance isn't at risk.
  • Turn on transaction alerts so you spot fraud quickly.
  • Check statements regularly.

What doesn't help

The padlock in the address bar only means the connection is encrypted. The malicious code runs on the real site, so HTTPS doesn't stop it. Antivirus on your computer usually won't see it either. See what HTTPS protects.

About browser extensions

No browser extension reliably blocks formjacking on a real store. Clipboard Guard blocks websites from reading your clipboard, which helps if you paste card numbers, but it doesn't protect forms. See autofill risks.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy