AI‑Powered Skimmer Campaign Hits Over 100 Retail Sites, Exposes 600,000 Card Numbers
A loosely organized, financially motivated threat group has leveraged open‑source artificial‑intelligence agent frameworks to launch a coordinated assault on more than one hundred e‑commerce sites, embedding malicious skimmer code that has harvested in excess of 600,000 credit‑card records.
The attackers repurposed publicly available AI‑agent toolkits—software originally designed to automate complex tasks such as web research or data extraction. By scripting the agents to locate vulnerable checkout pages, inject JavaScript skimmers, and exfiltrate payment data, the group achieved a level of automation that far exceeds traditional, manually‑operated skimmer deployments.
Security analysts say the campaign unfolded across a broad swath of online retailers, ranging from small niche boutiques to larger storefronts that host third‑party plugins. Once the AI agents identified a target, they deployed a lightweight script that silently captured card numbers, expiration dates and security codes as shoppers entered them, then relayed the information to a remote server controlled by the perpetrators.
The scale of the breach is notable: more than 600,000 credit‑card entries have been confirmed compromised, exposing millions of consumers to potential fraud and identity theft. Victims may face unauthorized charges, the need to replace cards, and the hassle of monitoring credit reports—costs that can quickly add up to significant financial and emotional strain.
Researchers who first uncovered the operation, cited by BleepingComputer, have alerted affected merchants and advised immediate remediation steps, including removal of unauthorized scripts, thorough code audits, and the implementation of stricter content‑security policies. Law‑enforcement agencies have been notified, and a handful of arrests have been reported in related cases, though the transnational nature of the actors complicates prosecution.
Experts warn that the use of openly available AI frameworks lowers the technical barrier for cybercriminals, making it easier for smaller groups to conduct large‑scale attacks. The incident underscores the need for retailers to adopt AI‑aware security practices, such as continuous monitoring for anomalous code changes and employing behavioral analytics that can flag the rapid, automated modifications typical of AI‑driven campaigns.
As AI tooling becomes more accessible, security professionals anticipate a rise in similar automated threat vectors. Industry bodies are calling for clearer guidelines on the responsible distribution of AI agent code, while regulators may look to tighten oversight of open‑source AI projects that could be weaponized. In the meantime, consumers are advised to remain vigilant, regularly review transaction histories, and consider using virtual card numbers where available to limit exposure.
Comments (0)
Be the first to comment.
Join the discussion