Skip to content
WP Hack FixEst. 2005

Card skimmer on my WooCommerce store

A card skimmer is a small piece of JavaScript added to your checkout page. It reads what customers type into the card fields and sends a copy to the attacker while the order goes through normally. Nothing looks broken, which is why these often run for weeks. This is the most serious thing that can happen to a WordPress store, and it needs to be treated carefully rather than quickly patched over.

We reply within 1 business day (Mon–Fri, 9–5 ET)

What you're seeing

  • Your payment processor, bank, or card network contacts you about fraud traced back to your store
  • Customers report card fraud shortly after ordering from you, sometimes several of them in a short period
  • A rise in chargebacks with no other explanation
  • Unfamiliar JavaScript loading on the checkout page, often from a domain you don't recognize
  • Recently modified files in your theme, in a payment plugin, or changed entries in the site's options table
  • The store itself works perfectly, and orders complete as normal

Why it happens

JavaScript injected into checkout

The code runs in the customer's browser and reads the card fields as they're typed. The details never reach your database, so nothing in your orders or your logs looks unusual.

A compromised plugin, theme, or admin account

The injection has to get onto the site somehow: an outdated plugin with a known vulnerability, a stolen administrator login, or hosting access captured in an earlier compromise.

Code hidden where you don't look

Skimmers are often stored in the database rather than in a file, added to a legitimate script, or loaded from an external domain through a single innocuous-looking line, which keeps them out of a casual file review.

Loading only on the checkout page

Many skimmers check which page is being viewed and stay dormant everywhere else, and some skip logged-in administrators. Browsing your own store proves nothing.

A fake or overlaid payment form

Some attacks replace the hosted payment field with a convincing look-alike form that collects the card details directly before handing the customer back to the real one.

What to do right now

Do this

  • Open your checkout in a private browsing window and look at the scripts the page loads, or ask someone technical to. Anything loading from an unfamiliar domain is worth flagging
  • Contact your payment processor or gateway and tell them you suspect a compromise. They will tell you what they need from you, and early contact is better than late
  • Change hosting, WordPress, and payment plugin passwords, and review every administrator account on the site
  • Preserve what you have: ask your host for access logs and file change history before anything is deleted or restored

Don't do this

  • Don't assume you're safe because your payments are processed elsewhere and you never store card numbers. A skimmer reads the details in the customer's browser before they ever reach your processor
  • Don't delete files and carry on trading as though nothing happened. Without knowing how it got in and how long it ran, you can't answer the questions your processor will ask
  • Don't tell customers everything is fine before anyone has checked. If card details were exposed, that statement is one you'll have to take back

How we fix it

  1. 1Examine the checkout the way a customer's browser sees it, including scripts loaded from outside your site, and identify exactly what was injected
  2. 2Trace it back through files, the database, and any external code to find every copy, plus the backdoor and the entry point behind it
  3. 3Establish, as far as the logs allow, when the injection went live and how long it was running, because those dates are what your processor will ask about
  4. 4Remove the skimmer, close the way in, rotate passwords, payment keys, and security keys, and harden the store
  5. 5Give you a written report in plain English that you can hand to your payment processor, and help you with what you need to tell your customers

Cleanups start at $349, with a money-back guarantee: if we can't clean your site, you don't pay.See pricing

Questions

We don't store card numbers. Doesn't that protect us?

Not from this. A skimmer works in the customer's browser, reading the keystrokes as the card number is typed into the form. It doesn't need your database, and it doesn't care whether payments are handled by an external processor. Not storing card data is the right choice, but it isn't a defense against injected checkout code.

Do I have to report this to anyone?

There may be obligations to your payment processor and to affected customers, and those are the merchant's responsibility rather than something we can take on for you. We're not lawyers and this isn't legal advice, so for anything beyond the technical picture you should talk to your processor and, if the exposure looks significant, your own legal adviser. What we do provide is the evidence and the written report you'll need for those conversations, and we'll help you word what you send to customers.

Does a card skimmer cost more to clean?

Our cleanup price is the same as any other cleanup, but card-skimming incidents may be quoted separately, because they usually involve more investigation and more help with the aftermath. We tell you the price before any work starts, so there's no surprise on the invoice.

Other symptoms

Hacked right now? Let's get it fixed.

Start your cleanup and we'll take it from there. If we can't clean it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)