Also known as web skimming, this is when a fraudster embeds a piece of malicious JavaScript code into the payment pages on an e-commerce website, effectively turning a legitimate website into a phishing page. It is like a digital version of ATM fraud, where criminals fit devices to cash machines in order to read the card data.
Web skimming scripts are designed to retrieve customer payment information such as card details. But fraudsters can also target websites to steal customer details and passwords.
It is considered a growing risk because fraudsters do not necessarily need cyber expertise to target a business in this way. If someone wants to buy a web skimming package, there are several dark-net marketplaces focused on the buying and selling of compromised servers.