Card skimmer on my WooCommerce store
A card skimmer is a small piece of JavaScript added to your checkout page. It reads what customers type into the card fields and sends a copy to the attacker while the order goes through normally. Nothing looks broken, which is why these often run for weeks. This is the most serious thing that can happen to a WordPress store, and it needs to be treated carefully rather than quickly patched over.
We reply within 1 business day (Mon–Fri, 9–5 ET)
What you're seeing
- Your payment processor, bank, or card network contacts you about fraud traced back to your store
- Customers report card fraud shortly after ordering from you, sometimes several of them in a short period
- A rise in chargebacks with no other explanation
- Unfamiliar JavaScript loading on the checkout page, often from a domain you don't recognize
- Recently modified files in your theme, in a payment plugin, or changed entries in the site's options table
- The store itself works perfectly, and orders complete as normal
Why it happens
JavaScript injected into checkout
The code runs in the customer's browser and reads the card fields as they're typed. The details never reach your database, so nothing in your orders or your logs looks unusual.
A compromised plugin, theme, or admin account
The injection has to get onto the site somehow: an outdated plugin with a known vulnerability, a stolen administrator login, or hosting access captured in an earlier compromise.
Code hidden where you don't look
Skimmers are often stored in the database rather than in a file, added to a legitimate script, or loaded from an external domain through a single innocuous-looking line, which keeps them out of a casual file review.
Loading only on the checkout page
Many skimmers check which page is being viewed and stay dormant everywhere else, and some skip logged-in administrators. Browsing your own store proves nothing.
A fake or overlaid payment form
Some attacks replace the hosted payment field with a convincing look-alike form that collects the card details directly before handing the customer back to the real one.
What to do right now
Do this
- Open your checkout in a private browsing window and look at the scripts the page loads, or ask someone technical to. Anything loading from an unfamiliar domain is worth flagging
- Contact your payment processor or gateway and tell them you suspect a compromise. They will tell you what they need from you, and early contact is better than late
- Change hosting, WordPress, and payment plugin passwords, and review every administrator account on the site
- Preserve what you have: ask your host for access logs and file change history before anything is deleted or restored
Don't do this
- Don't assume you're safe because your payments are processed elsewhere and you never store card numbers. A skimmer reads the details in the customer's browser before they ever reach your processor
- Don't delete files and carry on trading as though nothing happened. Without knowing how it got in and how long it ran, you can't answer the questions your processor will ask
- Don't tell customers everything is fine before anyone has checked. If card details were exposed, that statement is one you'll have to take back
How we fix it
- 1Examine the checkout the way a customer's browser sees it, including scripts loaded from outside your site, and identify exactly what was injected
- 2Trace it back through files, the database, and any external code to find every copy, plus the backdoor and the entry point behind it
- 3Establish, as far as the logs allow, when the injection went live and how long it was running, because those dates are what your processor will ask about
- 4Remove the skimmer, close the way in, rotate passwords, payment keys, and security keys, and harden the store
- 5Give you a written report in plain English that you can hand to your payment processor, and help you with what you need to tell your customers
Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing
Questions
We don't store card numbers. Doesn't that protect us?
Not from this. A skimmer works in the customer's browser, reading the keystrokes as the card number is typed into the form. It doesn't need your database, and it doesn't care whether payments are handled by an external processor. Not storing card data is the right choice, but it isn't a defense against injected checkout code.
Do I have to report this to anyone?
There may be obligations to your payment processor and to affected customers, and those are the merchant's responsibility rather than something we can take on for you. We're not lawyers and this isn't legal advice, so for anything beyond the technical picture you should talk to your processor and, if the exposure looks significant, your own legal adviser. What we do provide is the evidence and the written report you'll need for those conversations, and we'll help you word what you send to customers.
Does a card skimmer cost more to clean?
Our cleanup price is the same as any other cleanup, but card-skimming incidents may be quoted separately, because they usually involve more investigation and more help with the aftermath. We tell you the price before any work starts, so there's no surprise on the invoice.
Other symptoms
- Visitors get redirectedYour site sends people to spam, scam, or adult sites, often only on mobile or from Google.
- "This site may be hacked"Google shows a warning in search results, or Chrome shows a red "Deceptive site ahead" screen.
- Strange pages in GoogleJapanese, pharma, or casino pages you never created show up under your domain.
- Your host suspended youYour hosting company took the site offline or quarantined files for malware.
- Your site sends spamYour host or email provider says your server is sending spam or phishing emails.
- You're locked outYour admin password stopped working, or there are admin users you didn't create.
- It keeps coming backYou cleaned the site, and the malware was back within days.
- Fake login pagesSomeone is hosting fake bank or Microsoft login pages in a hidden folder on your site.
- Pharmacy spam in GoogleYour search listings mention pills or pharmacies, even though your pages look normal.
- A scanner says I'm infectedWordfence, Sucuri, or another plugin reports malware you can't get rid of.
Hacked right now? Let's get it fixed.
Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.
We reply within 1 business day (Mon–Fri, 9–5 ET)