Payment card data theft (skimming)
A compromised CDN script on a payment page intercepts card data as users type it — before it reaches the API. The API’s payment processing is never touched. The skimmer operates entirely in the user’s browser, leveraging the trust established by a script tag on the checkout page. Ticketmaster, British Airways, Newegg, and hundreds of other organizations experienced this between 2018 and 2020.