Report: a group known as Keeper has breached at least 570 online e-commerce portals since 2017; 85% of the victims' sites were running Magento software
Context & Ripple Effects
The Keeper report lands in a well-documented arc of Magento-focused skimming: an unauthenticated exploit published in 2019 put hundreds of thousands of Magento storefronts within reach of any attacker, and the platform's long tail of self-hosted shops has been the recurring victim pool since.
Keeper is one operator in a broader criminal ecosystem — Magecart crews have moved from storefront exploits to infrastructure-level hunting like scanning unsecured AWS S3 buckets, and the same playbook hit Shopify rival Volusion, delivering malicious JavaScript to thousands of stores through a single breach.
First-order effects
- Merchants running self-hosted Magento stores — 85% of Keeper's known victims — face immediate pressure to audit their checkout pages for injected skimmer code and patch the vulnerabilities that made the platform the dominant target.
- Shoppers who bought from the 570+ compromised portals since 2017 have had card data exposed to a group whose operations span years, not a single incident.
Second-order effects
- Hosted platforms gain a security selling point: every high-profile Magento breach pushes merchants toward rivals like Shopify, whose centralized model removes the patching burden that Keeper exploited — a dynamic already visible in the Volusion compromise, where one upstream breach cascaded to thousands of tenants.
- Security vendors and card networks respond with detection tooling and stricter compliance enforcement on storefront integrity, as seen when the UK's NCSC directly warned over 4,000 stores about Magecart-driven customer-data theft.
Third-order effects
- If the pattern holds — persistent groups like Keeper exploiting the self-hosted long tail while regulators escalate warnings — responsibility for checkout security migrates structurally from individual merchants to platforms, shrinking the viable market for unmanaged e-commerce software.
- Skimming becomes a durable service economy rather than opportunistic hacking: specialized groups divide labor between exploit discovery, infrastructure targeting, and monetization, which raises the baseline threat every online store must price in.
The trend: Card-skimming groups are industrializing attacks against self-hosted e-commerce platforms, steadily shifting merchant trust — and regulatory attention — toward centrally managed storefronts.