Why You Should Never Use Your Main Bank Card for Online Shopping Again

Most people assume the danger is a fake website. In practice, some of the worst breaches have happened on real, trusted sites. The technique is called formjacking, and it belongs to a family of attacks known collectively as Magecart...

Share
Why You Should Never Use Your Main Bank Card for Online Shopping Again

Every time you type your card number into a checkout page, you are trusting two things: the website and every third-party script that website has secretly loaded in the background. Most shoppers only think about the first one. And that gap is where a lot of money disappears.

According to the Nilson Report, the leading trade publication covering the global payment card industry, worldwide card fraud losses reached $33.41 billion in 2024. That figure covers credit, debit, and prepaid cards, and the bulk of it is not someone cloning a physical card at an ATM. It is fraud that happens when a card is not physically present, the kind that occurs entirely online, where a shopper types their real card number into a browser and never sees what happens to it after.

This is not a reason to panic about online shopping, though. There are other things to think about.

The Checkout Page Is Not Always What It Looks Like

Most people assume the danger is a fake website. In practice, some of the worst breaches have happened on real, trusted sites.

The technique is called formjacking, and it belongs to a family of attacks known collectively as Magecart, named after an early wave of incidents on Magento-powered shopping carts. It works like this: attackers do not need to break into a retailer's servers. They only need to compromise one third-party script the retailer already trusts, perhaps an analytics tool, a chat widget, or a marketing pixel. Once that script is altered, it reads whatever a shopper types into the payment form (card number, expiry date, CVV) and sends a copy to a server the attacker controls. The original transaction still goes through. The shopper gets their confirmation email. The retailer sees a normal completed sale. The card details are already gone.

British Airways learned this the hard way. In 2018, attackers linked to Magecart altered JavaScript on the airline's payment page and exposed the personal and payment details of around 429,612 customers over several weeks. The UK's Information Commissioner's Office eventually fined the airline £20 million in October 2020, down from an initially proposed £183.39 million. The airline had not been careless in any obvious sense. Its checkout page looked, and functioned, exactly as it should have.

This is the part that should unsettle anyone who reuses one card everywhere: the theft happens inside the browser, not on the server. A firewall cannot see it. The payment processor cannot see it. The retailer often does not even know until customers start reporting fraudulent charges weeks later.

Credentials, Not Brute Force, Open Most Doors

Verizon's 2025 Data Breach Investigations Report, now in its eighteenth year and drawn from tens of thousands of security incidents worldwide, adds another layer to this picture. Stolen credentials were involved in 88% of basic web application attacks that year, and third-party involvement in breaches roughly doubled compared with the year before.

Put plainly, a growing share of breaches trace back to a plugin, a vendor or a piece of borrowed code the retailer never wrote and does not fully control. A merchant can run a PCI-compliant checkout and still be exposed through a dependency three layers removed from anything its own security team touches. For a global shopper paying subscriptions, booking flights or buying from small independent stores across different countries, that risk compounds with every new merchant added to the list.

Disputing a fraudulent international charge afterwards is rarely quick. Depending on the bank, the card network and the country involved, resolving an unauthorised overseas transaction can involve documentation, waiting periods and back-and-forth that stretches on for weeks. For someone relying on that money to pay rent or restock inventory, a frozen or disputed balance is beyond a minor pain in the ass.

What Tokenization Actually Changes

What Tokenization Actually Changes

Every plastic card carries a Primary Account Number, the sixteen digits printed on the front. That number is permanent and tied directly to your account. Once it leaks, it stays compromised until the card is cancelled and reissued, which can take days.

EMVCo, the consortium behind global payment standards and jointly governed by Visa, Mastercard and the other major card networks, developed tokenization specifically to remove that permanence. Instead of handing merchants your actual account number, a tokenized card generates a surrogate value, a token, that stands in for it during the transaction. The real number is stored separately in a token vault and never touches the merchant's systems. If a retailer's checkout page is compromised by something like a formjacking script, what leaks is a token with no independent value outside the narrow context it was issued for, not the account number itself.

A virtual card takes that same principle and puts it directly in a shopper's hands. Instead of one static number used across every website you shop on, you generate a new, isolated card for the purchases that matter, and you can freeze, delete, or replace it in seconds if something looks wrong. In other words, your main balance, savings, or salary never touches the checkout page.

Best Practices, Even With A Virtual Card

A virtual card removes one major point of failure. It does not remove all of them. A few habits can therefore make the difference between a genuinely protected setup and a false sense of security.

  1. Use a separate virtual card for recurring subscriptions. If a streaming service or SaaS tool you barely use gets breached, you want to delete one card, not chase down every place your main number is stored.
  2. Fund it with only what you plan to spend. A virtual card linked to a small, purpose-specific balance limits how much is exposed even in a worst-case scenario.
  3. Check your transaction history regularly rather than waiting for a statement. Because virtual cards can be created and deleted instantly, catching an unfamiliar charge early means you can kill that specific card before it causes further damage, without touching anything else.
  4. Avoid reusing the same virtual card across many unrelated merchants. Part of the value of tokenization is isolation. One card, one purpose, keeps that isolation intact.
  5. Treat two-factor authentication as non-negotiable. Tokenization protects your card number. It does not protect your account login by itself.

The Bigger Shift

None of this is really about one bad website or one careless retailer. It is about how online payments were designed decades before anyone anticipated the scale of today's e-commerce ecosystem, where a single checkout page can depend on a dozen third-party scripts nobody at the retailer fully audits. Card-not-present fraud will not disappear because retailers get better at security. According to the Nilson Report's own projections, global fraud losses are expected to keep climbing over the next decade even as fraud-fighting technology improves, because transaction volume is growing faster than defenses can keep pace.

What has changed is how much control an individual shopper can take back. Apps like HostFi let users generate a Visa or Mastercard virtual card in minutes, funded directly from stablecoins or local fiat, and isolated entirely from their main savings. For someone shopping across borders, paying for subscriptions in a currency that is not their own, or simply tired of watching their bank account freeze for days after a disputed charge, that isolation could be the difference between one compromised checkout page costing you a canceled card, and the same situation costing you your life savings.