AI agents scale payment card theft across online retailers
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 24th, 2026.
Online retailers face faster payment theft and potential data loss from an AI-assisted campaign operating at low cost. The attacker used open-source AI agent frameworks to target companies, deploy card skimmers, and automate parts of the attack chain. Investigators reported more than six hundred thousand valid card records stolen from two companies and skimmers placed on at least 119 websites. Between September 10th and 15, the operator launched 105 attack waves and achieved varying levels of success against at least 27 companies.
Retailers, hospitality companies, airlines, and their customers can all be exposed when checkout systems are compromised. The campaign also created an operational risk beyond card theft. In some cases, the attacker instructed the AI tools to delete source card data after stealing it, which caused disruption for affected retailers. Leaders should recognize that AI can lower the cost and skill required to attack many organizations at once. Defenders should monitor checkout code, content delivery systems, cloud storage, databases, and persistence mechanisms for unauthorized changes. Continuously verify payment-page integrity and prepare incident plans for both card theft and destructive cleanup.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.