---
title: "Credit card theft campaign abuses Stripe to host stolen payment info"
url: https://daily.dev/posts/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info-bxtmvtzh5
source_url: https://www.bleepingcomputer.com/news/security/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info
type: article
source: "BleepingComputer"
published: 2026-06-04T20:51:14.862Z
updated: 2026-06-04T20:51:36.149Z
tags: ["stripe"]
reading_time: 3
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Credit card theft campaign abuses Stripe to host stolen payment info

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

A new Magecart campaign exploits Stripe's API infrastructure and Google Tag Manager to deliver and exfiltrate stolen payment card data from e-commerce checkout pages. The skimmer loads via a legitimate-looking GTM container, reads JavaScript payload from a Stripe customer record's metadata fields, captures payment details (card number, CVV, expiry, billing info), and stores stolen data as fake Stripe customer objects — effectively using Stripe as a covert data exfiltration backend. Because api.stripe.com is trusted by default in Content Security Policy rules, the attack bypasses typical network filters. A variant using Google Firestore instead of Stripe was also discovered. The campaign appears to have been active since at least December 24, 2025, targeting Magento/Adobe Commerce stores.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info>

## Similar posts on daily.dev

- [Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages](https://daily.dev/posts/long-running-web-skimming-campaign-steals-credit-cards-from-online-checkout-pages-kaszv4xrt) · The Hacker News · 0 upvotes · 0 comments
- [Fighting an active Magecart Campaign](https://daily.dev/posts/fighting-an-active-magecart-campaign-hmxjrgcqu) · Scott Helme · 0 upvotes · 0 comments
- [Hackers use pixel-large SVG trick to hide credit card stealer](https://daily.dev/posts/hackers-use-pixel-large-svg-trick-to-hide-credit-card-stealer-jvltp9ks7) · BleepingComputer · 0 upvotes · 0 comments
- [Anatomy of a WooCommerce Skimmer: A Technical Deep-Dive](https://daily.dev/posts/anatomy-of-a-woocommerce-skimmer-a-technical-deep-dive-7lkfziw4q) · Scott Helme · 0 upvotes · 0 comments

---

Tags: [#stripe](https://daily.dev/tags/stripe)

[View this post on daily.dev](https://daily.dev/posts/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info-bxtmvtzh5)
