Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
Refract AI Intelligence Digest
BLUF
AI automation is scaling e-commerce skimming attacks to compromise hundreds of sites simultaneously.
NEWS
A financially motivated group used AI agent frameworks to infect more than 100 online stores with malicious skimmers. This campaign successfully exfiltrated over 600,000 credit card records from customers across the targeted retailers.
Why I Care
This signals a dangerous evolution where AI lowers the skill barrier for large-scale financial crime, directly threatening merchant integrity and consumer financial security.
Next Steps
E-commerce operators must audit third-party scripts and enforce strict Content Security Policies immediately. Security teams should deploy AI-driven anomaly detection for web traffic within the next 30 days.
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]
Source: BleepingComputer ·