AI Agents Steal 600K Cards, Costing Attackers $25 per Site

Cybercriminals used AI tools to breach 119 sites, stealing over 600,000 credit card records at a low cost.
Key points
- AI agents stole over 600,000 credit card records from compromised sites.
- The campaign infected at least 119 websites with skimmer malware.
- The average cost per targeted company was approximately $25.
A cybercriminal group used open-source AI tools to attack online retailers. They stole over 600,000 credit card records. The campaign started in July and is still active.
Security firm Gambit reported the findings. The attacker compromised at least 119 websites. They injected software to steal payment data.
AI Tools Drive Automated Attacks
The attacker used three specific AI frameworks. One tool scanned for weaknesses. Another broke into systems to gain control. The third managed the overall operation.
A human operator gave brief goals. The AI handled the technical steps. This reduced the need for manual coding.
Skimmers Target Major Retailers
The attackers placed skimmer code on checkout pages. This software captures card numbers during purchases. They targeted companies with custom software.
BleepingComputer reported that large companies were hit. These include a major airline and a hospitality firm. The theft caused data loss for some victims.
Low Cost Enables Scale
Running these attacks is cheap. Researchers found costs of about $25 per target. This makes large-scale hacking feasible for small groups.
The automation allows for high volume. Attackers can test many sites daily. This creates a persistent threat for retailers.






