Card skimmer injection, credential stuffing, and web server compromise are the dominant attack vectors against e-commerce merchants. ARIA catches them automatically and satisfies PCI-DSS Requirement 10 without manual log review.
Any merchant that processes, stores, or transmits cardholder data is subject to PCI-DSS — regardless of size, revenue, or transaction volume. Level 4 merchants (under 1 million Visa transactions per year, which covers the vast majority of small and mid-size e-commerce businesses) are still required to complete a Self-Assessment Questionnaire and attest to compliance with the applicable controls.
Using a hosted payment processor like Shopify Payments or Stripe reduces your PCI scope because cardholder data is processed within their environment rather than yours. It does not eliminate your obligations entirely. You remain responsible for the security of the systems that connect to, integrate with, or interact with the payment environment. Your web server, your admin access systems, and your network infrastructure are in scope — and they need logging, monitoring, and file integrity controls.
Log all individual user access to system components in or connected to the cardholder data environment (CDE). Log all actions taken by root or administrative accounts. Log all access to audit trails. Retain logs for at least 12 months, with at least the most recent 3 months immediately available for analysis. Review logs daily — which in practice means automated correlation rules surface anomalies rather than a human reading every line. ARIA automates collection, retention, and daily review end-to-end.
Promptly detect and report failures of critical security controls, including monitoring and logging systems themselves. ARIA alerts on agent disconnections and logging gaps — satisfying the requirement to detect when your monitoring fails, not just when your systems are attacked.
Use a change-detection mechanism (file integrity monitoring) to alert personnel to unauthorized modification of critical files. File integrity monitoring is a direct, explicit PCI-DSS requirement. ARIA's FIM covers web server document roots, authentication configuration files, and payment application files. Unauthorized modification of a JavaScript file in your web root is an immediate alert.
Attackers compromise a web server and inject malicious JavaScript into checkout pages. The script copies card numbers and CVVs as customers type them, sending the data to a remote collection server. Detection: unauthorized modification of JavaScript files in the web root (FIM alert), unexpected outbound connections from the web server to unknown external IPs, loading of script domains not in your approved list.
Attackers use lists of breached username/password combinations to attempt logins on your site en masse. Because consumers reuse passwords across sites, a significant fraction succeed. Detection: failed login rate anomalies (hundreds of failures per minute from distributed IPs), successful logins from IPs in known credential-stuffing botnet ranges, account lockout volume spikes.
A compromised customer account is used to change the shipping address and place high-value orders. The goods arrive at an attacker-controlled address. Detection: shipping address modification followed immediately by a high-value order, from an account with no recent purchase history, from an IP the account has never used before.
Attackers gain shell access to the web server and capture card data processed in application memory — bypassing the payment processor's tokenization entirely. Detection: unusual process execution from the web server process (a PHP worker spawning a shell), unexpected outbound connections from the application server, new executable files appearing in web-accessible directories.
Non-compliance is a business risk, not just a regulatory one. The consequences of a breach at a non-compliant merchant are severe and compounding:
Card brand fines: Visa and Mastercard levy fines of $5,000–$100,000 per month on non-compliant merchants discovered after a breach. These are assessed to your acquiring bank, which passes them to you.
Liability for fraudulent charges: Non-compliant merchants may bear liability for all fraudulent charges traceable to a breach at their systems. There is no statutory cap on this liability.
Loss of card processing privileges: Your acquiring bank can terminate your card processing agreement upon discovery of a breach at a non-compliant merchant. For an e-commerce business, losing the ability to accept payment cards means losing the business.
State breach notification obligations: 47 states have data breach notification laws that require disclosure when payment card data is exposed. Class action lawsuits following e-commerce card data breaches are common and well-funded by plaintiff law firms.
Web server event logs: Every HTTP request hitting your checkout endpoints, at what rate, from which IPs. Anomalous request patterns — 10,000 POST requests to /checkout in 60 seconds — are correlated and surfaced.
File integrity monitoring: ARIA monitors your web server's document root for unauthorized file changes. The primary Magecart detection signal is a JavaScript file being modified without a corresponding deployment event. ARIA flags this within seconds of the write occurring.
Failed authentication patterns: Credential stuffing detection via failed login rate analysis. ARIA correlates failed authentication events across your web server logs and application event stream, surfaces volume anomalies, and flags IPs matching credential stuffing botnet ranges via OSINT enrichment.
Network connections from application servers: Your web server should make outbound connections to known services — payment gateway APIs, CDN endpoints, your own infrastructure. An outbound connection to an IP in Ukraine at 3am that the server has never contacted before is worth investigating. This is how Magecart skimmer C2 traffic looks at the network layer — ARIA catches it.
Admin access to payment systems: Privileged sessions to your payment application, database, and admin panel are logged and retained. Every admin login, every configuration change, every privileged query is timestamped and available for PCI auditor review.
Database query monitoring (Enterprise): Anomalous query volume, bulk SELECT operations on order or customer tables, and direct database access from accounts that normally don't touch production data are flagged. This catches both insider misuse and attacker data exfiltration after a server-side compromise.
A 30-minute call to scope your cardholder data environment, followed by ARIA deployment that begins satisfying Requirement 10 on day one. Findings report within 48 hours.
Book Free Assessment Book a Free AssessmentAll ARIA plans include file integrity monitoring and PCI-mapped compliance reports. Enterprise adds firewall log ingestion for network-level visibility and database query monitoring.
View Pricing