Select a theme from the list.
Insights

From our experts

Latest
Exploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftNightmareStresser Takedown Strikes at the DDoS-for-Hire EconomyAI-Assisted Exploit Chain Reached OpenAI Staff Accounts and Internal CodeRuntime npm Malware Slips Past Install-Time Supply Chain DefensesExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftNightmareStresser Takedown Strikes at the DDoS-for-Hire EconomyAI-Assisted Exploit Chain Reached OpenAI Staff Accounts and Internal CodeRuntime npm Malware Slips Past Install-Time Supply Chain Defenses
Security Insight

AI Attack Crews Turn Online Stores Into Industrial Card-Skimming Targets

AI Attack Crews Turn Online Stores Into Industrial Card-Skimming Targets
Photo by Pavel Danilyuk on Pexels

A financially motivated attacker is reportedly using several open-source AI agent frameworks to scan, compromise and manipulate online retail systems at scale. Researchers found evidence of more than 100 compromised websites and over 600,000 stolen payment-card records, demonstrating how autonomous tools can sharply reduce the cost of operating a broad web-skimming campaign.

A large payment-card theft campaign is showing how AI agents can move beyond reconnaissance and coding support to perform substantial portions of a real intrusion. According to research reported by BleepingComputer, an attacker combined three agent-based tools to discover vulnerable retailers, obtain access and deploy web skimmers across compromised infrastructure.

Automation Across the Attack Chain

The operation reportedly used Strix for scanning and vulnerability discovery, Cairn for autonomous exploitation, and Hermes for orchestration and post-compromise decisions. Instead of manually directing every command, the human operator supplied relatively short objectives and allowed the tools to perform extended runs against selected targets.

Researchers observed more than 100 attack waves over a five-day period, with varying levels of success against at least 27 companies. Evidence collected during the investigation connected the campaign to skimmers placed on at least 119 websites and more than 600,000 valid payment-card records taken from two businesses.

The attacker adapted the installation method to each environment. Techniques included modifying legitimate JavaScript, inserting scripts into checkout pages, poisoning content delivered through storage or content-distribution services, changing database fields and altering Kubernetes deployments. Persistence mechanisms were also used to restore skimming code after removal.

Why This Changes the Economics of Cybercrime

The campaign's estimated operating cost was only a few dollars to several dozen dollars for each target. That matters because agentic automation allows criminals to test far more organizations without building a large intrusion team.

I believe the primary warning is not that AI has created unfamiliar vulnerabilities. The agents succeeded by finding and combining existing weaknesses in custom applications, cloud permissions, deployment systems and website administration. Their advantage was speed, consistency and the ability to keep trying.

Defensive Priorities

  • Monitor checkout scripts and critical JavaScript files for unauthorized changes.
  • Restrict write access to content-delivery, storage and tag-management systems.
  • Use file-integrity monitoring across web servers and application containers.
  • Review Kubernetes changes, scheduled tasks and database modifications.
  • Prepare for destructive cleanup that may erase source data after theft.

Retailers should assume that attackers can now automate target selection and exploitation continuously. Defenses must become equally continuous, with rapid change detection and automated validation focused specifically on payment infrastructure.

Talk to our team →

Latest

Exploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureSep 24, 2026AI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsSep 24, 2026Microsoft Builds an Agentic Command Center for the Modern SOCSep 24, 2026OT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITSep 23, 2026Bifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionSep 23, 2026TrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorSep 23, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Windows LegacyHive Flaw Leaves Administrators Weighing Unofficial Protection6Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching