Event Type: On-Demand Webinars

The Crack in the Vault: How Banking Sites Unknowingly Expose Customer Data to Third Parties

the crack in the vault

Banks are trusted to protect our most private financial details, but new security research reveals a major gap between that promise and digital reality. Jscrambler’s analysis of financial institutions across the US and Europe reveals a critical vulnerability: sensitive customer and commercial data – such as loan amounts, account details, and hashed emails – is routinely leaked to third-party ad platforms.

Worse, these third-party browser scripts bypass traditional security perimeters and ignore privacy choices, capturing data before consent or even after a user selects “reject all.”

In this webinar, we analyzed data exposure cases documented across 14 US and European financial sites. We explained how scripts bypass cookie consent, map the paths sensitive data takes, and discussed the steps you should take to implement runtime controls to secure these flows.

Key Takeaways

Consent Failures

How tracking scripts run before banner interaction or ignore explicit “reject all” commands.

Financial Intent Leaks

How credit simulations quietly send exact loan amounts and terms to external ad networks.

Identity Exposure

The mechanics of how hashed emails, names, and tax IDs slip through default ad-tech matching.

Active Defense

How to deploy continuous client-side monitoring to block unauthorized exfiltration in real time.

Join Jscrambler’s security research team as we break down these findings and show you how to regain control of your client-side data.

Meet the speakers

Gareth Bowker
Jscrambler, Head of Security Research
https://www.linkedin.com/in/garethbowker/

Nathan Coppinger
Jscrambler, Product Marketing Manager
https://www.linkedin.com/in/nathan-coppinger-310171116/

David Alves
Jscrambler, Security Analyst
https://www.linkedin.com/in/dmmca/

5 Simple Steps to Zero Friction PCI DSS Compliance

During this session, Jscrambler’s Katia Kupidinova and Jeffrey Cleveland address how in five simple steps organizations can quickly comply to meet the upcoming deadline for PCI DSS v4, with the least amount of internal resources. Following this webinar, you’ll come away with a defined roadmap to PCI DSS v4 compliance that is applicable to all organizations of any size and budget.

In this webinar, we:
– Understand how to tackle a time-sensitive challenge with PCI DSS v4 compliance
– Get insights about the current state of compliance options and existing solutions
– Learn about the differences in cost and efficiency depending on the technology solution for compliance
– Get an overview of vendor evaluation and implementation timeline
– Learn about the 5 simple steps to accelerate compliance

Meet the Speakers
Katia Kupidonova
Product Marketing Manager at Jscrambler
https://www.linkedin.com/in/katia-kupidonova/

Jeffrey Cleveland
Pre-Sales Director at Jscrambler
https://www.linkedin.com/in/jeffrey-cleveland-7271a6164/

Payment Page Security with PCI DSS v4

Register for the webinar co-organized by ControlCase and Jscrambler to empower you with strategies in cybersecurity and compliance. We provide valuable insights into the emerging requirements of PCI DSS v4 and methods for mitigating security incidents and data breach risks, especially concerning payment pages.

In this webinar, we:
– Explore the digital skimming patterns through insights from Jscrambler’s Pedro Fortuna
– Gain access to a PCI v4 preparation Keynote: John Elliott delivers essential insights
– See a ControlCase service overview and Jscrambler demo
– See a panel discussion with industry experts, John Elliott, Pedro Fortuna, and Chad Leedy

Meet the Speakers
Pedro Fortuna
Jscrambler CTO & Co-founder
https://www.linkedin.com/in/pedrofortuna/

John Elliott
Jscrambler Security Advisor
https://www.linkedin.com/in/withoutfire/

Jeffrey Cleveland
Pre-Sales Director at Jscrambler
https://www.linkedin.com/in/jeffrey-cleveland-7271a6164/

Chad Leedy
Head of Strategic Accounts at ControlCase
https://www.linkedin.com/in/chadleedy/

Coalfire reviews the Jscrambler platform in meeting PCI DSS requirements 6.4.3 & 11.6.1

Join Jscrambler’s Jeffrey Cleveland and Coalfire’s Michael Burke in discussing and reviewing Jscrambler’s platform capabilities to comply with key requirements that elevate security and compliance benchmarks, particularly focusing on managing and monitoring scripts on payment pages.

In this webinar, we:
– Review Jscrambler platform as a solution to achieve scalable and easy compliance with PCI DSS v4
– Expert opinions about payment page security, compliance, and sensitive payment data protection
– Actionable strategies and industry-leading practices for digital skimming security
– Guidance on online payment page risks, and digital skimming attacks
– Summary of PCI DSS v4 e-skimming requirements 6.4.3 and 11.6.1

Meet the Speakers
Michael Burke
Principal Consultant, Payments and Cloud Advisory at Coalfire
https://www.linkedin.com/in/michael-burke-ph-d-82b47a1a2/

Shannon Moran
Sales Director at Jscrambler
https://www.linkedin.com/in/shmoran/

Jeffrey Cleveland
Pre-Sales Director at Jscrambler
https://www.linkedin.com/in/jeffrey-cleveland-7271a6164/

Goodbye PCI DSS v3.2.1, Hello PCI DSS v4

Jeremy King, Regional Head of Europe at the PCI Security Standards Council, and Jeffrey Cleveland, Pre-Sales Engineer at Jscrambler explore the intricacies of the new payment page requirements outlined in PCI DSS v4. Understand the rationale behind these changes with an operational approach to how organizations can adapt their payment processes accordingly.

In this webinar, we:
– Talk about the new PCI DSS v4 requirements 6.4.3 and 11.6.1 and what they are
– Learn about how to interpret the payment page security requirements within the new standard
– Understand the current challenges in the market and who are is affected by the standard
– Explain the timeline for implementation and compliance scheduled for 2025
– Present solutions that enable script business justification, integrity, detection, alerting, and control

Meet the Speakers
Jeremy King
Regional Head of Europe at PCI SSC
https://www.linkedin.com/in/jeremy-king-90a75328/

Jay Robinson
Regional Sales Director at Jscrambler
https://www.linkedin.com/in/jay-k-robinson/

Jeffrey Cleveland
Pre-Sales Director at Jscrambler
https://www.linkedin.com/in/jeffrey-cleveland-7271a6164/

Web Skimming Requirements in PCI DSS v4

Explore the critical requirements 6.4.3 and 11.6.1, focusing on combating the surge in web skimming attacks. Learn about the mechanisms behind these attacks, supply chain vulnerabilities, and effective detection/prevention solutions like CSP/SRI, scanners, and agents. Find out how Jscrambler can bolster your defenses.

In this webinar, we:
– Talk about the new PCI DSS v4 requirements 6.4.3 and 11.6.1 and what they are
– Discuss about the rise in web skimming attacks and how they happen
– Understand web skimming attacks’ detection and available solutions: scanners, CSP/SRI, synthetic agents, and agents
– Explore how these solutions contribute to compliance
– Present solutions for detection and prevention

Meet the Speakers
Katia Kupidonova
Product Marketing Manager at Jscrambler
https://www.linkedin.com/in/katia-kupidonova/

Jeffrey Cleveland
Pre-Sales Director at Jscrambler
https://www.linkedin.com/in/jeffrey-cleveland-7271a6164/

Debunking Free Obfuscation Myths: Towards Client-Side Protection

Discover the myths and dangers of using these seemingly accessible tools, which can pose significant risks to projects and developers. From introducing JavaScript code obfuscation as a technique to protect first-party code to the wide range of free obfuscation tools available online, our panel of client-side protection experts identify all the hidden dangers, compare solutions, and explain how Jscrambler can help you protect your code.

In this webinar, we:
– Introduce JavaScript code obfuscation: basic concepts and practical applications
– Explore free obfuscation tools: what they offer and their limitations
– Understand the expectations and challenges of using these tools
– Explain hidden dangers: how free obfuscation tools can affect the security and reliability of a project
– Explain how Jscrambler is a unique obfuscation solution on the market

Meet the Speakers
Gustavo Marques
Product Manager at Jscrambler
https://www.linkedin.com/in/gustavo-marques-62a2a911/

Katia Kupidonova
Product Marketing Manager at Jscrambler
https://www.linkedin.com/in/katia-kupidonova/

Jeffrey Cleveland
Pre-Sales Director at Jscrambler
https://www.linkedin.com/in/jeffrey-cleveland-7271a6164/

Understanding the New PCI DSS Requirements to Prevent E-commerce Skimming Attacks

The new PCI DSS 4.0 is mandatory for assessments after 31st March, 2024. These new requirements are aimed at ensuring the integrity of pages where payment is taken on an e-commerce website.

In this webinar we will discuss what is changing with the new requirements and how Jscrambler addresses these specific sections, helping in the prevention of skimming attacks.

In this webinar, we:
– Discuss what is changing with PCI DSS 4.0
– Show how skimming attacks are conducted
– Explore how Jscrambler addresses these specific sections of PCI DSS 4.0
– Highlight how Jscrambler provides one of the best protections on the market

Meet the Speaker
John Elliott
Jscrambler Security Advisor
https://www.linkedin.com/in/withoutfire/

State of Application Security in UK Banking

The fast-growing digital transformation in banking poses greater security challenges for members of the financial system. This technological revolution has led to the emergence of Fintechs and has greatly accelerated the digital presence of incumbents.

But while technological innovation enables banks to provide richer customer experiences and shorten their time to market, it requires organizations to reassess their security posture and commitment to compliance.

In this webinar, we:
– Discuss how digital transformation is shaping the UK banking landscape
– Explore the emerging regulations around data protection and open banking
– Frame the technological landscape of web and mobile banking apps in UK banking
– Present first-hand data on the current state of application security in UK banking
– Detail some key security considerations to improve the overall security posture

Meet the Speakers
Filipe Lima
Marketing Team Lead at Jscrambler

Richard Smith
Enterprise Architect at Golden Switch Limited

Mohamed Gamil
CEO and Founder of dotConnect

Lessons Learned From Securing 2 Billion E-commerce User Sessions

In 2021, 90% of all data breaches involved a web application and 44% included PII records.

Within a sample of 2 billion E-commerce user sessions secured by Jscrambler, we find unique insight into how attackers attempt to leak data and hijack E-commerce websites. Understanding these security weaknesses is key for retailers to minimize their exposure to software supply chain attacks.

In this webinar, we:
– Explore the current state of cybersecurity in E-commerce
– Detail the key threats of data leakage and customer hijacking
– Present unique data and insights from 2 billion user sessions
– Explain how retailers can take the first steps to reducing their exposure to attacks

Meet the Speakers
Filipe Pereira
VP of Engineering at Jscrambler
https://www.linkedin.com/in/fipereira/

Don Duncan
Sales Director, Eastern NA & Canada at Jscrambler
https://www.linkedin.com/in/donjduncan/