Google Tag Manager Skimmer Steals Credit Card Info From
Magento Site
By Puja Srivastava
Published: 2025-02-06 · Archived: 2026-04-05 13:42:28 UTC
At Sucuri, we are committed to protecting websites from malware and other cyber threats. Recently, we were
contacted by a customer who had experienced credit card data theft from their Magento-based eCommerce
website. After an extensive investigation, we were able to trace the malware responsible for what was happening
back to the Google Tag Manager script and assist in restoring the site’s security. We have detailed a previous
similar infection here Malicious Activities with Google Tag Manager.
What was noticed?
The customer reached out to us with a concerning issue: they had discovered that sensitive customer data,
specifically credit card details, was being stolen from their Magento site. This type of breach is especially
troubling because it can lead to financial losses, loss of customer trust, and significant damage to the website’s
reputation.
What is a Google Tag Manager?
Google Tag Manager (GTM) is a free tool from Google that allows website owners to manage and deploy
marketing tags on their website without needing to modify the site’s code directly. It simplifies the process of
adding and updating tags for things like Google Analytics, AdWords, Facebook Pixel, and more, making it easier
for marketers to track website activity and optimize campaigns without involving developers every time a change
is needed.
The