Find notable cyber news and cases, enriched with sources, timelines, and signals.

Two companies' credit card records stolen in retail skimming operation

Data Leak
First reported
Last updated
Happening score
H score 46
1 unique sources, 1 articles

Summary

Hide ▲

A confirmed theft of more than 600,000 valid card details from two companies has expanded a payment-data exposure tied to a retail skimming operation. The records were taken during an attack campaign active since at least July and still ongoing on September 22. The same operation used open-source AI agent frameworks and skimmer malware, increasing the risk of fraud and downstream card abuse.

Related Happenings

Open-source AI agent retail skimming campaign

Campaign
H score53 First: 23.09.2026 19:20 Last: 23.09.2026 19:20 Sources 1

How related: A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.

About this happening: A financially motivated threat actor is running an AI-agent-driven skimming campaign against online retailers, stealing payment card data at scale. The operation h...

Credit card skimmer malware deployed on retailer websites

Malware Activity
H score53 First: 23.09.2026 19:20 Last: 23.09.2026 19:20 Sources 1

How related: the attacker stole more than 600,000 valid card details from two companies and deployed skimmer malware on the websites of five other organizations to collect payment data.

About this happening: Skimmer malware has been injected across at least 119 websites, creating a large-scale payment-data theft operation. The payload captured card details from retailer checko...

Timeline

  1. 23.09.2026 19:20 2 articles · 2h ago

    More than 600,000 valid card details stolen from two companies

    Initial Disclosure

    Gambit says a financially motivated threat actor using open-source AI agent frameworks stole more than 600,000 valid card details from two companies and deployed skimmer malware on five other organizations' websites to collect payment data. The campaign has been active since at least July and was still ongoing as of September 22.

    Show sources