Back to all lessons
Awareness Lessons
2 weeks ago

AI-Powered Skimming Campaign Steals 600K Credit Cards from 100+ Retail Sites

A threat actor weaponized open-source AI agent frameworks to automate the full attack lifecycle — from vulnerability scanning to skimmer deployment — across more than 100 e-commerce websites, exfiltrating over 600,000 credit card records. The use of AI dramatically lowered the barrier to entry, allowing a sophisticated, scalable attack for as little as $12,000–$18,000 in operational costs. This illustrates how AI is reshaping the threat landscape by enabling adversaries to conduct enterprise-scale attacks with minimal resources. Retailers with unpatched storefronts, weak input validation, or inadequate monitoring are now prime targets for these automated, low-cost campaigns. The incident underscores that the speed of AI-assisted attacks has likely outpaced traditional, manual security response cycles.

Tactical Insight

Immediate actions

  • Audit all internet-facing e-commerce platforms for known vulnerabilities and apply patches or mitigations immediately.
  • Deploy file integrity monitoring on web server directories to detect unauthorized script injections or skimmer code.
  • Scan all active web pages for unauthorized third-party scripts using tools like Subresource Integrity (SRI) checks.

Detection measures

  • Implement real-time alerting on anomalous outbound data transfers from web servers, particularly to unknown or foreign IP addresses.
  • Enable Web Application Firewall (WAF) rules specifically targeting automated scanning patterns and common skimmer injection techniques.
  • Monitor server logs for high-frequency, systematic vulnerability probing consistent with AI-driven reconnaissance behavior.

Long-term improvements

  • Adopt a Content Security Policy (CSP) to restrict which scripts can execute on payment and checkout pages, limiting skimmer effectiveness.
  • Establish a regular vulnerability management program with automated scanning cadences aligned to PCI DSS requirements for cardholder data environments.
  • Implement network segmentation to isolate payment processing systems from general web infrastructure, reducing lateral movement risk.