Credit card skimmer malware deployed on retailer websites
Malware Activity
Summary
Hide ▲
Show ▼
Skimmer malware has been injected across at least 119 websites, creating a large-scale payment-data theft operation. The payload captured card details from retailer checkout flows and was tied to the theft of more than 600,000 valid card records. The malware was repeatedly restored after removal, increasing the chance of continued loss and making cleanup harder.
Related Happenings
Two companies' credit card records stolen in retail skimming operation
Data Leak
H score46
First: 23.09.2026 19:20
Last: 23.09.2026 19:20
Sources 1
How related:
the attacker stole more than 600,000 valid card details from two companies
About this happening:
A confirmed theft of more than 600,000 valid card details from two companies has expanded a payment-data exposure tied to a retail skimming operation. The records were tak...
Two companies' credit card records stolen in retail skimming operation
Data LeakHow related: the attacker stole more than 600,000 valid card details from two companies
About this happening: A confirmed theft of more than 600,000 valid card details from two companies has expanded a payment-data exposure tied to a retail skimming operation. The records were tak...
GorgonAgora fake .shop card-skimming campaign
Campaign
H score84
First: 05.06.2026 11:38
Last: 05.06.2026 11:38
Sources 1
About this happening:
The GorgonAgora campaign is using 5,714 fake .shop storefronts to steal payment data, widening card-theft risk across brand-impersonation checkout pages. The operation has...
GorgonAgora fake .shop card-skimming campaign
CampaignAbout this happening: The GorgonAgora campaign is using 5,714 fake .shop storefronts to steal payment data, widening card-theft risk across brand-impersonation checkout pages. The operation has...
BeatBanker Android phishing campaign targeting Brazilian users
Campaign
H score82
First: 12.03.2026 09:56
Last: 12.03.2026 09:56
Sources 1
About this happening:
A BeatBanker Android phishing campaign is targeting Brazilian users, creating a risk of device compromise and payment theft. The lure uses Google Play Store lookalike...
BeatBanker Android phishing campaign targeting Brazilian users
CampaignAbout this happening: A BeatBanker Android phishing campaign is targeting Brazilian users, creating a risk of device compromise and payment theft. The lure uses Google Play Store lookalike...
Timeline
-
23.09.2026 19:20 2 articles · 2h ago
AI agent campaign steals card data from online retailers
Initial DisclosureGambit reported that a financially motivated threat actor was using open-source AI agent frameworks to automate scanning, exploitation, orchestration, and cleanup against online retailers, stealing more than 600,000 valid card details from two companies and deploying skimmer malware on the websites of five other organizations. The campaign had been active since at least July and was ongoing as of September 22, with at least 119 websites compromised, 105 distinct attack waves launched between September 10 and 15, and cleanup instructions that wiped Magento card-data fields after exfiltration.
Show sources
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers — www.bleepingcomputer.com — 23.09.2026 19:20
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers — www.bleepingcomputer.com — 23.09.2026 19:20