Interestana
Home/News/AI Agents Steal 600K Credit Cards, Infect 100+ Sites
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

AI Agents Steal 600K Credit Cards, Infect 100+ Sites

A sophisticated threat actor has employed open-source artificial intelligence agent frameworks to execute large-scale attacks against online retailers, successfully stealing over 600,000 credit card records and infecting more than 100 websites with malicious skimmers. This financially motivated campaign highlights the growing threat of AI-powered cybercrime, enabling attackers to automate complex operations and achieve significant scale. The attackers utilized AI agents to automate the process of finding vulnerabilities, injecting malicious JavaScript code, and exfiltrating sensitive payment data from compromised e-commerce platforms. The scale of the operation suggests a high degree of technical proficiency and strategic planning by the threat actor.

The campaign's methodology involves the deployment of AI agents that can autonomously scan for and exploit vulnerabilities in web applications, specifically targeting online stores. Once a vulnerability is identified, the AI agents are programmed to inject "skimmer" code, a type of malicious script designed to capture payment card details as they are entered by unsuspecting customers. This code is often disguised to evade detection by standard security measures. The compromised websites then serve as conduits for the attackers to collect vast amounts of sensitive financial information, including credit card numbers, expiration dates, and CVV codes. The sheer volume of stolen credit card data, exceeding 600,000 records, indicates the extensive reach of this operation.

Security researchers who uncovered the campaign noted that the threat actor's use of AI agent frameworks represents a significant evolution in cyberattack capabilities. These frameworks allow for the creation of autonomous agents that can learn, adapt, and execute tasks with minimal human intervention, making them highly effective for persistent and widespread attacks. The attackers were able to compromise over 100 distinct online retail sites, demonstrating the broad applicability of their AI-driven attack strategy. The compromised sites span various sectors within e-commerce, suggesting that no specific niche was exclusively targeted, but rather a general vulnerability in web application security was exploited.

The implications of this attack extend beyond the immediate financial losses incurred by consumers and businesses. It underscores the urgent need for enhanced cybersecurity measures, particularly in the realm of e-commerce. The ability of AI agents to automate reconnaissance, exploitation, and data exfiltration at this scale poses a formidable challenge to existing security defenses. The use of open-source AI frameworks by malicious actors further democratizes access to these advanced attack capabilities, potentially lowering the barrier to entry for cybercriminals. The ongoing investigation aims to identify the specific AI agent frameworks used and to develop more robust defenses against such AI-driven threats, emphasizing the critical role of AI in both offensive and defensive cybersecurity strategies.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next