MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via BleepingComputer

AI-driven attack wave hits online retailers, swiping over 600,000 card records

Image via BleepingComputer
Image via BleepingComputer

A financially motivated attacker is using open-source AI agent frameworks to automate large-scale attacks against online retailers, compromising at least 27 companies and deploying card-skimmer malware on multiple websites. The campaign, active since July, has stolen more than 600,000 valid credit card details, with the AI agents handling scanning, exploitation, and post-compromise actions under brief human instructions. Researchers observed over 100 attack waves in a five-day period, with skimmers injected via various methods including modified JavaScript, poisoned CDN content, and altered database fields.

Expanded Detail

The attack chain relies on three open-source AI frameworks working in sequence: Strix performs reconnaissance and vulnerability scanning, Cairn executes exploitation to gain access, and Hermes orchestrates the overall campaign using a "SOUL - Red Team Operator" persona with 121 skills. Between August 23 and 31 alone, Strix ran 146 times against 138 hosts, accumulating 633 hours of scanning activity. The human operator, believed to be Chinese-speaking, provided only brief strategic instructions before letting the agents operate autonomously.

The financial scale of the operation is notable: researchers found an OpenRouter account showing roughly $7,000 spent over four weeks, with total estimated costs between $12,000 and $18,000. This translates to an average cost of about $25 per targeted company, making the operation remarkably cost-efficient. The attacker also prioritized targets using a traffic-ranking service, focusing on sites running custom software likely to contain exploitable vulnerabilities.

Context

This campaign could signal a shift in cybercrime economics, where AI agents dramatically lower the barrier to large-scale attacks. Small and mid-sized retailers may face heightened risk as attackers can now target hundreds of companies simultaneously with minimal human oversight. Consumers whose card data was stolen could experience fraud, identity theft, and financial losses. The operational disruptions from wiped databases may also harm retailers' ability to process legitimate transactions. If this model proves successful, other financially motivated actors could adopt similar AI-driven approaches, potentially normalizing automated crime waves across multiple industries.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Global probe ties North Korean group to mass device compromise and crypto theft · Cybersecurity
AI-Powered Malware 'ClosedQuorum' Automates Post-Compromise Actions on Windows · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers.” Browse more stories.