U.S. BANK PAYMENT SMART: Trends in payments cybercrime and prevention basics

June 2026

Monthly tips, tools and best practices

Know the threats

Trends in payments
cybercrime

Find out more

First line of defense

Top 3 preventative
action you can take

Find out more

Cover your bases

Small steps that
lead to big protection

Find out more

Tis’ the season

Reopening your
seasonal business

Find out more


A message from your account manager

Phishing/smishing, ransomware and credential harvesting remain the most common and damaging attack methods targeting payment systems. This month, we’ll explore each of these cybercrimes and look at actions you can take to potentially make your business less of a target.

Trends in payments cybercrime

Work team in meeting room getting cybersecurity training.

Identity and access threats and fraud remain top cybersecurity concerns, with stolen credentials and phishing attacks driving the majority of breaches according to cybersecurity* experts. 

High transaction volumes and sensitive financial data make payment systems a prime target. Breaches can drive immediate financial loss and erode customer trust.

Understanding the different attack types is an important first step in mitigating risks within your own business. Below, we review the most common threats.

Ransomware
Criminals use malicious software to infiltrate systems and steal payment data. Once inside, attackers may redirect transactions or exfiltrate sensitive information.  Ransomware locks or steals access to files, systems or networks and demands payment for restoration.

Phishing and smishing
Attackers use deceptive emails or text messages that impersonate vendors to trick employees into sharing confidential data, including credentials, one-time codes, account numbers and passwords. These messages often appear legitimate (e.g., invoices or electronic faxes) but contain malicious links or attachments that can compromise systems.

Skimming
Digital skimming infects eCommerce websites with malicious code—often JavaScript (JS) “sniffers”—that is difficult to detect. Once embedded, these tools capture payment data during transactions without the merchant or customer’s knowledge. Physical skimming devices can also be placed on POS systems to steal card data.

Invoice and vendor fraud
Fraudsters impersonate legitimate vendors to alter payment details or request inflated payments, frequently bypassing standard verification controls in business-to-business and eCommerce environments.

Fraudulent authorization testing
Also known as enumeration attacks, these occur when automated bots send thousands of small authorization attempts—often just a few cents—using stolen card numbers to identify which accounts are still valid. Once validated, card data can be sold on the dark web or immediately used for fraudulent transactions. These attacks can also drive excessive transaction fees for merchants.

Elavon notification
If you believe your business, third-party processor or software provider has experienced a data security incident possibly impacting the risk of payment card data, notify Elavon Global Client Security. This helps ensure compliance with reporting requirements to the card brands (Visa, Mastercard, Discover, American Express, and others). Email Elavon Global Client Security at adcqueries-NA@elavon.com.

Back to top

The top 3 preventive action you can take

Small business owner working on a laptop in her shop.

Keeping your payment device compliant—meaning secure, up to date and aligned to best practices—is one of the most effective ways to reduce cyber risk. It sounds simple, but for many busy merchants, it’s often overlooked or deprioritized.

  1. Keep point-of-sale (POS) software up to date at all times.
    Cybercriminals frequently exploit known security flaws in outdated software. We send automatic software updates to your devices but there are steps you must take to ensure your device is benefiting from our automation:
    • Turn on auto-download in POS settings
    • Keep your POS turned on and connected to the internet, including when you’re closed, so that auto-downloads can take place
    • Settle open batches at the close of every business day. They must be settled in order for a scheduled auto-download to occur.
    • If we contacted you indicating that your device is too old to handle software updates, please act quickly to upgrade to a newer device version.
  2. Strengthen security with layers.
    Compliance isn’t just updates, it includes multiple layers of protection: 
    • Encryption and tokenization secure card data at rest and in transit
    • Solutions like Safe-T combine authentication, encryption and tokenization across transactions
    • EMV 3D Secure helps verify online purchases using real-time risk analysis (available through Converge)
  3. These controls make it much harder for attackers to access or misuse data—even if they get in.

  4. Stay PCI DSS compliant.
    The Payment Card Industry Data Security Standard (PCI DSS) is required for any business handling card data. Regular reviews and timely revalidation are also required. Staying compliant helps protect your business and aligns with proven security practices

    If your PCI DSS validation has lapsed, your account manager can assist and share tools such as PCI Compliance Manager which provides proactive support to help you complete the PCI DSS Compliance Validation Process. Support includes an Online PCI Validation Tool, 365/24/7 PCI portal access tracking progress and PCI Qualified Security Assessor (QSA)-supported help desk to answer your questions.

The bottom line. Compliance is proactive defense. It closes gaps, strengthens security layers and lowers your exposure to everyday threats. Falling behind leaves you vulnerable to attacks that are both common and preventable.

Back to top


Cover your bases: Small steps that lead to big protection

Restaurant employee team members engaging with a tablet.

Cybersecurity protects your systems; fraud prevention protects your transactions. Both matter and small businesses don’t need big budgets to make a big impact. Start with the essentials:

Require strong authentication for all users: Add a second login step for critical systems using tools such as multi-factor authentication (MFA). And give employees only what they need access to and nothing more.

Phishing training: Teach employees to spot suspicious emails. Employees need to also understand what sensitive data is, how to protect it and what to do when something seems off.

Monitor activity: Watch for unusual logins, transactions or behavior and scan systems and websites for vulnerabilities.

  • Tip #1: Check your batches before you settle. If you see a transaction (especially a large refund) that you don't recognize or seems out of place for your business, you should check your sales receipts to verify its legitimacy.
  • Tip #2: If your eCommerce system has an option to set velocity filers, set those up to monitor the rate and pattern of transactions to detect unusual activity that could indicate card testing, account takeover or brute-force attacks. 

Strengthen your passwords: Weak passwords can be a top risk. Improve them by updating passwords regularly, using strong combinations (upper/lowercase, numbers, symbols) or passphrases (e.g., B1gMac&frieS), and requiring unique logins. Never share credentials.

Consider your eCommerce website: If you use an outside vendor to develop and maintain your eCommerce website, have them verify that your HTML source code is well hidden. You’d be surprised how often this detail gets overlooked and how much risk it presents.

  • Tip #1: Make sure all links within HTML source code are masked and includes a ‘No Index’ tag.
  • Tip #2: Check that your shopping cart software has the latest security patches, remove inactive plugins and make sure your SSL certificate is current.
  • Tip #3: If you experience a fraud incident connected to a hosted payment page, delete all existing links to the hosted payment page and replace with any provided updated links.

By focusing on strong access controls, employee training and continuous monitoring, you can dramatically reduce risk—protecting your business, your customers and your reputation.

Contact us if you experience a data security incident

Again, if you believe your business, third-party processor, or software provider has experienced a data security incident possibly impacting the risk of payment card data, notify Elavon Global Client Security at adcqueries-NA@elavon.com.

Back to top 


Reopening your seasonal businesses 

Smiling food service employee preparing ice cream at a counter.

If you’ve been waiting all year to sell your product or service, don’t cut yourself short by delaying reopening your account and promptly reordering terminals. Call customer service 2—4 weeks out to ensure you’re ready to accept payments as soon as your customers are ready to buy.

Back to top


Who do you call?

Call Customer Care at 800-725-1243 or email custsvc@elavon.comwith questions about: 

  • Daily account activity and funding
  • Point-of-sale terminal or PC product issues
  • Your monthly billing statement

Contact your Customer Account Manager with questions about: 

  • Managing card processing for your business
  • Other payment solutions or services that may be available to you

Payments Insider

  • View statements, reports, file downloads and more
  • Securely view your account information anytime, anywhere

Elavon Status Site makes it easy to get information 24/7 on a service disruption.

Powered By GrowthZone