Most skimming incidents are never named. The shop is small, the disclosure is a line in a bank’s fraud report, and the story ends there. A handful became public because the victim was large enough that regulators, researchers and the press all took an interest. Those cases are worth knowing, not for the brand names but because each one shows a different way the attack arrives.
What follows is a short tour, in date order, with the lesson from each.
Ticketmaster UK · June 2018
The skimmer arrived inside a customer-service chat widget supplied by a third party, Inbenta, which Ticketmaster had placed on its payment pages. When the supplier’s code was compromised, every page loading it served the skimmer too. The Information Commissioner’s Office later found that a bank had flagged a pattern of fraud pointing at Ticketmaster months before the company began monitoring the traffic on its payment page, and that Ticketmaster had not been watching how often the supplier changed its script. The ICO put the potential exposure at more than nine million customers across Europe and fined Ticketmaster UK £1.25 million in November 2020.
The lesson: a chat widget has no business on the page where card numbers are typed. Every script on that page is part of your attack surface, whoever wrote it.
British Airways · August to September 2018
Between 21 August and 5 September 2018, a script injected into the airline’s website and mobile app copied the payment details of around 430,000 customers. The skimmer was small, tailored to BA’s own checkout, and sent the stolen data to a domain registered to look like part of the airline’s infrastructure. In July 2019 the ICO announced its intention to fine BA £183 million; in October 2020, after representations and the collapse in airline revenue during the pandemic, it settled on £20 million, at the time still the largest penalty it had issued. The regulator’s finding was blunt: the failure was one of basic security hygiene, not an exotic attack.
The lesson: a targeted skimmer is written to look like it belongs. Nothing failed, nobody complained, and it ran for two weeks on one of the busiest checkouts in the country.
Newegg · August to September 2018
Within days of the BA incident, researchers found the same crew inside Newegg, the US electronics retailer. The pattern was identical: a short skimmer on the payment page, active from mid-August to mid-September, exfiltrating to a lookalike domain registered in advance. Newegg never published a figure for affected customers. The two cases together established that the same group was running patient, targeted operations against large merchants rather than spraying small ones.
The lesson: the crews that go after big targets prepare. The domain was registered weeks before the code went live.
VisionDirect · November 2018
For five days in early November 2018, the UK contact-lens retailer and its sister sites in seven other European countries loaded a script from g-analytics.com, a domain chosen to be mistaken for Google Analytics by anyone glancing at the network traffic. Customers who logged in or checked out in that window had their card details, including the security code, copied as they typed.
The lesson: skimmers hide in plain sight by imitating the services a checkout already talks to. A domain that looks familiar is not a domain you approved.
Macy’s · October 2019
The US department store disclosed that for about a week in October 2019 a skimmer had been present not only on its checkout page but on the page where customers manage saved cards in their account. That second placement mattered: it meant details could be stolen from people who were not buying anything at the time, simply by their viewing a wallet page.
The lesson: the checkout is not the only page that handles card data. Anywhere a card number is displayed or edited needs the same scrutiny.
Claire’s · April to June 2020
Claire’s closed all of its physical shops on 20 March 2020 as the pandemic took hold. Within weeks, attackers registered the domain claires-assets.com, and by the end of April a skimmer was live on the online stores of both Claire’s and its sister brand Icing, attached to the submit button of the checkout form. It stayed there until 13 June, when researchers at Sansec found it. The timing was not a coincidence: with every shop shut, all the sales were online, and the attackers knew it.
The lesson: attackers read the news. A sudden shift of business online is a signal to them as much as to you.
Warner Music Group · April to August 2020
Warner disclosed that a number of its US online stores, operated for it by an external provider, had been skimmed from 25 April to 5 August 2020, more than three months. Names, addresses, and full card details including the security code were exposed. The company did not say which stores, and the breach was reported to regulators rather than discovered by them.
The lesson: outsourcing the store does not outsource the responsibility. If a provider runs your checkout, their monitoring is your monitoring, and you need to know what it is.
Magento 1 · September 2020
Magento 1 reached end of life on 30 June 2020, which meant no more security patches for the tens of thousands of shops still running it. A few weeks later an exploit for it was advertised on a criminal forum for $5,000. Over the weekend of 12 and 13 September, an automated campaign used it to inject a skimmer into 1,904 stores in about 48 hours, the largest single Magecart campaign recorded at the time. Sansec, who tracked it, estimated around ten thousand shoppers had their details taken over that weekend.
The lesson: an unpatched platform is not a risk, it is a schedule. Once the exploit exists, the only question is which weekend.
What the big cases have in common
Put side by side, the incidents sort into three routes in. Ticketmaster and Warner came through a supplier. British Airways, Newegg, VisionDirect, Macy’s and Claire’s were targeted, with code written for one checkout and a domain chosen to blend in. Magento 1 was mass and automated, with no interest in who the victims were.
Three things recur regardless of route. The skimmer was small and quiet, and the payment always went through. It was found from outside, by a researcher or a bank, rather than by the merchant. And in every case where a regulator looked, the finding was the same as the ICO’s on BA: not an exotic attack, but ordinary hygiene left undone: scripts nobody had listed, pages nobody was watching, platforms nobody had patched.
The short version
The famous Magecart cases are famous because the victims were large, not because the attacks were clever. A chat widget, a lookalike domain, a wallet page, a shop closed by lockdown, an outsourced store, an unpatched platform. Each is a door that was open. The defence, then as now, is to know every script on the payment page and to notice when it changes.
