Two companies' credit card records stolen in retail skimming operation
Data Leak
Summary
Hide ▲
Show ▼
A confirmed theft of more than 600,000 valid card details from two companies has expanded a payment-data exposure tied to a retail skimming operation. The records were taken during an attack campaign active since at least July and still ongoing on September 22. The same operation used open-source AI agent frameworks and skimmer malware, increasing the risk of fraud and downstream card abuse.
Related Happenings
Open-source AI agent retail skimming campaign
Campaign
H score53
First: 23.09.2026 19:20
Last: 23.09.2026 19:20
Sources 1
How related:
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
About this happening:
A financially motivated threat actor is running an AI-agent-driven skimming campaign against online retailers, stealing payment card data at scale. The operation h...
Open-source AI agent retail skimming campaign
CampaignHow related: A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
About this happening: A financially motivated threat actor is running an AI-agent-driven skimming campaign against online retailers, stealing payment card data at scale. The operation h...
Credit card skimmer malware deployed on retailer websites
Malware Activity
H score53
First: 23.09.2026 19:20
Last: 23.09.2026 19:20
Sources 1
How related:
the attacker stole more than 600,000 valid card details from two companies and deployed skimmer malware on the websites of five other organizations to collect payment data.
About this happening:
Skimmer malware has been injected across at least 119 websites, creating a large-scale payment-data theft operation. The payload captured card details from retailer checko...
Credit card skimmer malware deployed on retailer websites
Malware ActivityHow related: the attacker stole more than 600,000 valid card details from two companies and deployed skimmer malware on the websites of five other organizations to collect payment data.
About this happening: Skimmer malware has been injected across at least 119 websites, creating a large-scale payment-data theft operation. The payload captured card details from retailer checko...
Timeline
-
23.09.2026 19:20 2 articles · 2h ago
More than 600,000 valid card details stolen from two companies
Initial DisclosureGambit says a financially motivated threat actor using open-source AI agent frameworks stole more than 600,000 valid card details from two companies and deployed skimmer malware on five other organizations' websites to collect payment data. The campaign has been active since at least July and was still ongoing as of September 22.
Show sources
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers — www.bleepingcomputer.com — 23.09.2026 19:20
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers — www.bleepingcomputer.com — 23.09.2026 19:20