Open‑Source AI Bots Compromise 27 Firms, Exfiltrate Half a Million Credit Cards
Security firm Gambit Security disclosed that a suite of open‑source artificial‑intelligence agents has penetrated the networks of 27 companies, siphoning roughly 600,000 credit‑card records and deploying covert payment‑page skimmers across the affected retailers' e‑commerce sites.
The breach was uncovered during a routine audit of compromised merchant platforms. Gambit analysts traced the intrusion to AI‑driven scripts that autonomously scanned for vulnerable checkout pages, injected malicious JavaScript, and then harvested payment data in real time. The agents left behind persistent code that continues to capture card numbers from unsuspecting shoppers.
Open‑source AI tools, originally released for legitimate research and development, can be repurposed as low‑cost, highly adaptable weapons. Because the underlying models and codebases are publicly available, threat actors can modify them to suit specific attack vectors without needing deep programming expertise. In this case, the agents leveraged machine‑learning techniques to identify checkout forms, bypass basic bot‑detection mechanisms, and mimic human browsing behavior.
The scale of the theft is notable. Six hundred thousand credit‑card details represent a substantial blow to both consumers and merchants, potentially exposing victims to fraud and increasing charge‑back costs for the businesses involved. Retailers whose sites were compromised now face the dual challenge of notifying affected customers and overhauling their payment infrastructure to eradicate the hidden skimmers.
Cybersecurity experts warn that the incident underscores a broader shift in the threat landscape. As generative AI becomes more accessible, attackers are increasingly automating reconnaissance, exploitation, and data exfiltration tasks that previously required coordinated human effort. This automation shortens the window between discovery of a vulnerability and successful exploitation, raising the overall risk to organizations of all sizes.
Industry groups have called for faster adoption of advanced fraud‑prevention tools, such as real‑time transaction monitoring and AI‑enhanced web‑application firewalls, to counter the new breed of automated attacks. Some regulators are also considering guidelines that would require merchants to perform regular integrity checks on client‑side code and to disclose AI‑related security risks to customers.
Gambit Security recommends that firms conduct immediate code reviews of all payment‑page scripts, employ integrity‑checking mechanisms like Subresource Integrity (SRI), and monitor network traffic for anomalous data‑exfiltration patterns. As open‑source AI models continue to proliferate, security teams will need to stay vigilant, integrating threat‑intelligence feeds that specifically track AI‑driven malware variants.
The episode serves as a warning that the convenience of open‑source AI can be a double‑edged sword. While the technology fuels innovation across sectors, its unrestricted availability also equips malicious actors with powerful new tools. Stakeholders—from developers to policymakers—must collaborate to establish safeguards that preserve the benefits of AI while curbing its misuse.
Comments (0)
Be the first to comment.
Join the discussion