Skip to content
AI news, tool reviews, expert columns, prompts, agents and practical automation workflows.
News

AI Agents Used in Attack Campaign That Stole 600,000 Credit Card Details From Online Shops

Security researchers report an ongoing campaign where AI agents autonomously breached at least 27 companies, stealing over 600,000 active credit card records from online shops between July and September 2026.

News Published 25 September 2026 3 min read Maya Turner
Security researcher analyzing AI agent attack data from campaign that stole 600,000 credit card records from online shops
Imagen destacada del articulo fuente

Security researchers have uncovered an ongoing attack campaign in which AI agents autonomously breached at least 27 companies and stole data from over 600,000 active credit cards. The attacks, which targeted 105 online shop projects between July and September 2026, represent one of the first large-scale documented uses of AI agents in automated financial cybercrime.

The campaign, active since July 2026 and continuing as of late September, used AI agents to carry out attacks with minimal human intervention, according to analysts tracking the activity. Between September 10 and September 15, the attackers escalated operations against 105 projects, leading to confirmed system compromises at 27 companies with varying degrees of access. At least two of those firms had their entire credit card databases copied, yielding more than 600,000 unexpired card records.

Scale of the automated breach

The use of AI agents marks a significant escalation in automated cybercrime. Unlike traditional scripted attacks that follow fixed patterns, AI agents can adapt to defenses, make decisions about which vulnerabilities to exploit, and pivot between targets without waiting for human commands. Security researchers noted that the AI agents appeared to operate largely autonomously throughout the campaign.

The attackers focused on e-commerce infrastructure, targeting online shops and payment processing systems. The 105 projects under attack ranged from small independent stores to larger retail operations. While the full financial impact remains under assessment, the theft of 600,000 active credit cards represents a substantial data breach event by any measure.

Key facts
Active campaign period July 2026 – ongoing (September 2026)
Projects targeted 105
Companies compromised 27
Credit card records stolen Over 600,000 (unexpired)
Attack method AI agents operating with high autonomy

Why this matters for AI and security professionals

For developers and security teams working with AI tools and agents, this campaign demonstrates that the same capabilities being built for legitimate automation can be repurposed for大规模 fraud. The attack vector is not a theoretical risk but an active, verified threat. Security teams managing e-commerce platforms, payment APIs, and AI-powered monitoring systems need to reassess whether their defenses can distinguish between legitimate automated traffic and malicious AI agents.

The campaign also raises questions about AI agent safety and the ease with which autonomous systems can be weaponized. If AI agents can independently identify targets, exploit vulnerabilities, and exfiltrate data, traditional rate-limiting and signature-based detection may prove insufficient.

Limited public information on techniques

The security researchers who identified the campaign have not yet published detailed technical breakdowns of the AI agents’ specific methods, likely to avoid providing a playbook for copycat attackers. What is known is that the agents targeted online shop platforms, exploited system vulnerabilities, and maintained persistence across multiple days. The attackers appear to have used a combination of publicly available AI models and custom tools, though the exact architecture remains undisclosed.

The ongoing nature of the attacks means that additional companies may be compromised. Security teams are advised to audit their e-commerce infrastructure for signs of unusual automated behavior dating back to July 2026.

Practical next checks for affected businesses

Online shop operators and e-commerce platform providers should review access logs for anomalous automated traffic patterns between July and September 2026. Payment processors should check for unusual API call volumes that could indicate data exfiltration. Companies that discover evidence of compromise should contact the relevant security research group for indicators of compromise.

The full technical report from the security researchers is expected once the campaign is contained and affected organizations have been notified.

Source: Heise KI – https://www.heise.de/news/Freitag-Lizenzen-fuer-Flugdrohnen-Abschuss-Switch-Pirat-soll-an-Nintendo-zahlen-11465223.html

Source

Heise KI Publicacion original: 2026-09-25T04:15:00+00:00