Find notable cyber news and cases, enriched with sources, timelines, and signals.

Credit card skimmer malware deployed on retailer websites

Malware Activity
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

Skimmer malware has been injected across at least 119 websites, creating a large-scale payment-data theft operation. The payload captured card details from retailer checkout flows and was tied to the theft of more than 600,000 valid card records. The malware was repeatedly restored after removal, increasing the chance of continued loss and making cleanup harder.

Related Happenings

Two companies' credit card records stolen in retail skimming operation

Data Leak
H score46 First: 23.09.2026 19:20 Last: 23.09.2026 19:20 Sources 1

How related: the attacker stole more than 600,000 valid card details from two companies

About this happening: A confirmed theft of more than 600,000 valid card details from two companies has expanded a payment-data exposure tied to a retail skimming operation. The records were tak...

GorgonAgora fake .shop card-skimming campaign

Campaign
H score84 First: 05.06.2026 11:38 Last: 05.06.2026 11:38 Sources 1

About this happening: The GorgonAgora campaign is using 5,714 fake .shop storefronts to steal payment data, widening card-theft risk across brand-impersonation checkout pages. The operation has...

BeatBanker Android phishing campaign targeting Brazilian users

Campaign
H score82 First: 12.03.2026 09:56 Last: 12.03.2026 09:56 Sources 1

About this happening: A BeatBanker Android phishing campaign is targeting Brazilian users, creating a risk of device compromise and payment theft. The lure uses Google Play Store lookalike...

Timeline

  1. 23.09.2026 19:20 2 articles · 2h ago

    AI agent campaign steals card data from online retailers

    Initial Disclosure

    Gambit reported that a financially motivated threat actor was using open-source AI agent frameworks to automate scanning, exploitation, orchestration, and cleanup against online retailers, stealing more than 600,000 valid card details from two companies and deploying skimmer malware on the websites of five other organizations. The campaign had been active since at least July and was ongoing as of September 22, with at least 119 websites compromised, 105 distinct attack waves launched between September 10 and 15, and cleanup instructions that wiped Magento card-data fields after exfiltration.

    Show sources