Hash Drift

PCIComplianceHubLast updated

The change-detection finding that a script already present on a payment page now hashes differently from its baseline, meaning its contents changed while its URL stayed the same. It is the signal Requirement 11.6.1 exists to catch, because an attacker who modifies a script that is already authorised leaves both the inventory and the allow list intact. Drift is not by itself evidence of an attack: providers update their own scripts routinely, so a drift finding has to be reviewed rather than assumed benign or malicious.