Your payment provider is secure. Is your payment page?
Wednesday, 23rd September at 11:00 BST | 12:00 CET / SAST
Speakers
-
Martin Petrov, CTO - PCI, Integrity360
-
Leor Eliashiv, UK&I Country Manager, Reflectiz
Outsourcing payment processing can reduce PCI scope, but it does not outsource the security of the customer's checkout journey. A payment provider can remain secure while attackers compromise the web environment around it—using malicious scripts, tag managers and even trusted services to steal payment data inside the customer's browser.
Join Leor Eliashiv from Reflectiz and Martin Petrov from Integrity360 for a thought-leadership session examining how the modern web-skimming attack surface has evolved beyond the payment provider itself. Using recent Magecart campaigns that abused trusted infrastructure including Stripe APIs and Google Tag Manager, the session will show how attackers can impersonate legitimate payment experiences, execute malicious code in the browser and move stolen data through services that security teams already trust. Recent research illustrates precisely why this distinction matters: the payment provider itself does not need to be compromised for customers' payment data to be put at risk.
Attendees will walk through the anatomy of a modern checkout attack—from initial compromise and malicious script execution to card-data capture and exfiltration—and explore why server-side controls, traditional scanning, allowlists and other conventional defenses may have limited visibility into what is actually executing in the consumer's browser. PCI SSC has identified this browser-side attack surface as a significant payment-security concern and introduced specific PCI DSS v4.0.1 controls to address payment-page script integrity and tamper detection.
The discussion will conclude with the practical implications for merchants using hosted payments, embedded payment forms and other third-party payment integrations: where responsibility still sits, what PCI DSS expects, and how organizations can gain meaningful visibility across the checkout experience without assuming that a trusted payment provider eliminates the wider risk. PCI SSC's current SAQ A guidance reinforces this distinction for merchants using embedded payment forms, requiring them to address susceptibility to script-based attacks even where account-data functions are outsourced.
