Threat actors installed malware on over 440 online stores to steal the credit card details and other payment data of unsuspecting customers, Europol revealed in a recent press release.
It’s unclear exactly how many customers have been affected by this widespread cybercrime campaign, spanning 17 countries. Europol said the owners of all 443 affected sites have been notified about the security breach.
“Digital skimming attacks can go undetected for a long time. Payment or credit card information stolen as a result of these criminal acts is often offered for sale on illicit marketplaces on the darknet,” Europol said.
In a two-month-long operation, Europol worked with the European Union Agency for Cybersecurity (ENISA), law enforcement from several countries, and private cybersecurity companies, including Group-IB and Sansec, to combat the massive card skimming campaign. The operation, spearheaded by Greece, is part of the EMPACT (European Multidisciplinary Platform Against Criminal Threats) initiative.
‘Javascript Sniffers’ Used to Steal Payment Data
According to Group-IB, the threat actors used “JavaScript sniffers” — malicious scripts surreptitiously installed on websites — to steal victims’ payment data.
Group-IB detected 23 distinct families of Javascript sniffers during its investigations, including ATMZOW, health_check, FirstKiss, FakeGA, AngryBeaver, Inter, and R3nin.
Card skimming, also known as e-skimming, formjacking, or Magecart attacks, has been around for many years. Criminals often sell the data stolen from such attacks on the dark web, and victims may not know their privacy has been compromised until it’s too late.
“Typically, customers remain unaware of the compromise until the criminals exploit their stolen details to conduct unauthorized transactions,” Group-IB said.
According to the cybersecurity company, between the second half of 2021 and the first half of 2022, over 320,000 credit or payment cards were compromised globally using sniffers, marking a four-fold increase from the previous year.
How to Protect Yourself From Card Skimming Attacks
Cybercriminals usually take advantage of major events to launch malicious schemes, like card skimming attacks. Ahead of the Black Friday online shopping frenzy in November 2023, cybersecurity firm Malwarebytes reported a surge in card skimming and phishing scams.
It’s important to take steps to protect yourself from card skimming. Europol recommends:
- Using anti-malware software with web skimming detection capabilities, such as Malwarebytes Premium
- Using secure passwords and multi-factor authentication
- Keeping all your software up-to-date by allowing automatic updates
- Only shopping on trusted sites with the HTTPS padlock
In addition to these tips, we recommend using a virtual private network (VPN) like NordVPN to keep your internet activities from prying eyes. Read our guide to shopping safely online for more security tips.
Watch the video below to learn more about Europol’s latest campaign:
For more news, follow us on X (Twitter), Threads, and Mastodon!

