:

AI AGENTS STEAL 600K CREDIT CARDS FROM 100+ SITES

AI DESK2 MIN READ
WED, SEP 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A threat actor is deploying open-source AI agent frameworks to compromise hundreds of online retailers at scale, harvesting over 600,000 credit card records through payment skimmers.

Cybersecurity researchers have identified a financially motivated threat actor leveraging AI agent technology to automate large-scale attacks against e-commerce platforms. The campaign uses open-source AI frameworks to scan and compromise more than 100 websites, injecting payment skimmers that capture credit card data during checkout. The attackers have successfully stolen 600,000+ credit card records, making this one of the largest automated retail card theft operations documented. The use of AI agents significantly amplifies the attack surface by enabling the threat actor to identify vulnerabilities and deploy malware across multiple targets with minimal manual intervention. Open-source AI agent frameworks—tools designed to automate complex tasks and decision-making—have been repurposed for malicious reconnaissance and exploitation. These systems scan target websites, identify payment processing systems, and deploy skimming code without requiring extensive manual configuration for each victim. Retailers affected span multiple industries and geographic regions. The skimmers intercept payment card information at the point of transaction, before encryption occurs, allowing attackers to harvest data in real-time. Victims typically remain unaware until fraudulent charges appear or payment processors detect anomalies. Security researchers recommend retailers implement robust intrusion detection systems, conduct regular security audits, and monitor for unauthorized code injection. Payment processors advise monitoring for unusual transaction patterns and implementing additional fraud detection measures. The incident highlights growing threats posed by accessible AI tools being weaponized for cybercrime. As AI agent frameworks become more sophisticated and widely available, defenders face escalating challenges in securing infrastructure against automated, adaptable attacks. Organizations are urged to update security protocols and increase incident response capabilities to address threats leveraging AI-driven exploitation techniques.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The FBI is investigating claims that hackers breached its systems and stole personal information from thousands of current and former employees. The bureau confirmed the breach investigation in a statement Wednesday.

JUST NOWAI Desk

The National Highway Traffic Safety Administration is investigating comma.ai, an autonomous driving software company, following multiple crashes and deaths involving vehicles using its devices. Federal investigators have documented at least 5 incidents where comma.ai-equipped cars struck slow or stopped vehicles.

JUST NOWAI Desk

A limited-permission Kubernetes user can potentially gain full control of a Google Cloud organization by exploiting the Google Kubernetes Config Connector. The vulnerability represents a classic confused deputy problem in cloud infrastructure.

3H AGODev Desk

Enterprise infrastructure management systems are under sustained attack, with critical vulnerabilities being exploited before or immediately after vendor patches become available, according to a new InfraTrust report.

3H AGODev Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.