Organizations pursuing PCI DSS compliance are being warned that compliance controls alone do not prevent client-side payment data theft, particularly when third-party scripts and outsourced payment flows are involved. Commentary highlights that changes to PCI DSS v4-related guidance (including updated SAQ A language for merchants using PCI-compliant payment service providers) can reduce mandated anti-skimming requirements, increasing the risk that merchants “trust but don’t verify” protections around browser-executed code and third-party dependencies.
Separately, tokenization guidance emphasizes that tokenization is distinct from encryption and is intended to reduce exposure by replacing sensitive values (e.g., PANs) with non-sensitive tokens, potentially reducing PCI scope when implemented correctly. The same guidance cautions that implementation pitfalls are common and that using encryption as a stand-in for tokenization can leave organizations at risk—reinforcing that data protection architecture (e.g., tokenization) and client-side/script visibility controls address different parts of the payment-data threat surface, and both may be necessary to mitigate modern skimming techniques such as MirrorMask targeting select Stripe merchants via script/API redirection and reverse-proxy interception.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
In April 2025, some merchants using Stripe were targeted by the MirrorMask digital skimmer. The campaign redirected Stripe scripts and API calls to a fake Stripe site and used a reverse proxy to harvest payment data while preserving a normal checkout experience.
In 2025, PCI DSS SAQ A was changed to remove requirements 6.4.3 and 11.6.1 for merchants that outsource payment processing to PCI DSS-compliant payment service providers. The change reduced explicit anti-skimming and script-monitoring obligations for those merchants under SAQ A.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.