← Back to Crime & Security

AI-Powered Attack Steals 600,000 Credit Card Records from Global Retailers

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A financially motivated cyber threat actor has compromised more than 100 online retailer websites worldwide, stealing over 600,000 credit card records in a coordinated campaign leveraging open-source artificial intelligence frameworks. The attack, detected on September 23, 2026, marks a significant escalation in the use of automated tools to target e-commerce infrastructure for financial gain.

The threat actor, identified as a human operator appearing to be based in China, utilized AI-powered agents to automate the identification and exploitation of vulnerabilities across hundreds of retail platforms. Unlike previous campaigns that relied on manual reconnaissance or static malware, this operation employed dynamic AI frameworks capable of adapting to security defenses in real time. The attackers successfully infiltrated payment processing systems, extracting sensitive financial data including card numbers, expiration dates, and security codes.

The breach spans a global network of online merchants, affecting businesses across multiple continents. While the specific identities of all compromised retailers have not been fully disclosed, industry analysts indicate that small to mid-sized e-commerce platforms were primary targets due to perceived weaker security postures compared to major enterprise systems. The sheer volume of stolen data—exceeding 600,000 records—suggests a highly efficient operation designed to maximize yield before detection.

Security experts note that the use of open-source AI agent frameworks lowers the barrier to entry for sophisticated attacks, allowing operators to deploy complex intrusion techniques without developing proprietary tools. The attackers appear to have focused exclusively on financial motivation, with no evidence of data destruction or political messaging accompanying the theft. The stolen credit card information is likely intended for immediate sale on dark web marketplaces or for direct fraudulent transactions.

Retailers affected by the breach are currently working to secure their systems and notify customers of potential exposure. Financial institutions have begun monitoring for suspicious activity linked to the compromised accounts, though the full extent of fraud remains unclear. The incident highlights a growing trend where criminal groups integrate generative AI into their attack chains, increasing both the speed and scale of data theft operations.

Questions remain regarding the total number of targeted sites that may not yet have detected the intrusion. Investigators are also examining whether the stolen data has already been monetized or if it remains in transit on underground channels. As cybersecurity firms scramble to patch the specific vulnerabilities exploited by the AI agents, the incident serves as a stark warning of the evolving capabilities facing the global retail sector.

Discussion

0 / 2000