Security researchers uncovered an AI‑driven skimming campaign that has stolen more than 600,000 payment records since July 2026, targeting retail sites worldwide.

Security researchers have uncovered a massive, AI‑driven skimming operation that has siphoned more than 600,000 payment records since July 2026, targeting retail websites across the globe and deploying malware on hundreds of compromised sites.

How the AI agents operate

The campaign leverages custom‑built AI agents that automatically scan e‑commerce platforms for vulnerable checkout pages. Once a target is identified, the agents inject malicious JavaScript that captures credit‑card numbers, expiration dates and CVV codes in real time.

Unlike traditional skimmers that require manual deployment, these agents use machine‑learning models to adapt to different site architectures, bypassing common defenses such as content‑security policies and input validation checks.

Scale of the breach

Since the operation began in July 2026, the stolen data set has grown to include over 600,000 distinct payment records, according to the researchers’ analysis of leaked databases posted on underground forums.

The compromised sites span a range of industries, from fashion retailers to electronics marketplaces, and are primarily hosted on shared‑hosting environments that lack robust isolation between customers.

Malware payloads delivered

In addition to skimming scripts, the attackers drop secondary payloads that install remote‑access trojans (RATs) and cryptominers. These payloads enable the threat actors to maintain persistence, exfiltrate additional data and monetize infected servers.

  • Remote‑access trojans provide ongoing control of compromised servers
  • Cryptominers generate illicit revenue for the operators
  • Data exfiltration tools harvest further credentials and personal information

The dual‑use nature of the malware complicates remediation, as victims must address both financial data loss and the broader security compromise of their web infrastructure.

Response and mitigation

Experts advise immediate steps for affected merchants: audit all third‑party scripts, enforce strict content‑security policies, and deploy runtime application self‑protection (RASP) solutions that can detect anomalous script behavior.

Consumers should monitor bank statements for unauthorized charges and consider using virtual card numbers where available, as these can be revoked without affecting the primary account.

The use of AI agents marks a significant escalation in the automation of web‑based financial theft, making large‑scale skimming operations faster and harder to detect.

For a detailed technical breakdown, see TechRadar’s coverage of the AI‑driven Chinese hack.