
Come talk to us about your PCI v4.0 needs at Booth 4. While you're at it, enter our drawing for a pair of Ray-Ban Meta Glasses!



Date: March 5, 2025
Time: 9:25 AM
Location: Balboa at Park MGM
This session will share findings from over 2,000 e-commerce client-side forensic investigations. We have seen a dramatic increase in attacks specifically on ecommerce sites using iframes to host a payment page from a 3rd party service provider.
These findings emphasize the importance of PCI DSS requirements 6.4.3 and 11.6.1 in helping combat e-commerce skimming trends. For example, in 100% of the cases where card data skimming was occurring, the security failure was present on the merchant’s referring page and not because of a malicious script on the 3rd party hosted payment page. This finding clearly indicates that the main skimming risks are on the merchant’s side, not on the service provider’s side.
Merchants are responsible for monitoring the scripts that they include on their websites (PCI DSS requirement 6.4.3) and checking for the presence of malicious scripts and behaviors on any payment or referring payment pages (PCI DSS requirement 11.6.1). The trends we’ve found can help merchants see the practical application of these requirements, and be empowered to secure their websites against threat actors.
I'd love to hear your thoughts or answer any questions about my presentation. Send an email to jb@securitymetrics.com.
The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.