← Blog · · df00tech

Financially Motivated Actor Uses Open-Source AI Agent Frameworks to Deploy Skimmers at Scale, 600K Cards Reportedly Stolen

security-news technique

What Happened

According to a report from BleepingComputer, a financially motivated threat actor has been leveraging open-source AI agent frameworks to automate attacks against online retailers at scale. The campaign reportedly compromised more than 100 sites with payment card skimmers and resulted in the theft of over 600,000 credit card records. Technical specifics — the exact frameworks used, the initial access vector, and the skimmer code itself — were not detailed in the available reporting.

Why It Matters

If accurate, this represents an escalation in how automation is applied to a well-established attack pattern: e-commerce skimming (Magecart-style attacks). Using AI agent frameworks to orchestrate reconnaissance, exploitation, and skimmer deployment across many targets simultaneously could let a single operator compromise and maintain a much larger footprint of victim sites than manual operations typically allow. Online retailers of any size, along with their customers whose payment data is processed on affected checkout pages, are the parties at risk. The scale reported (100+ sites, 600K+ cards) suggests a broad, largely opportunistic targeting pattern rather than a narrow, bespoke intrusion.

What Defenders Should Watch For

  • Monitor for unauthorized modifications to checkout/payment pages, including changes to JavaScript served on payment forms and unexpected third-party script inclusions.
  • Watch for anomalous, high-volume, or unusually consistent probing/scanning traffic patterns against e-commerce platforms and CMS admin panels, which could indicate automated, agent-driven reconnaissance rather than manual attacker activity.
  • Review web application firewall and CDN logs for spikes in requests to known e-commerce plugin vulnerabilities or admin login endpoints across multiple properties in a short window.
  • Implement Subresource Integrity (SRI) and Content Security Policy (CSP) controls on payment pages to detect or block unauthorized script injection.
  • Ensure e-commerce platforms, plugins, and extensions are patched promptly, since skimmer campaigns typically ride on known, unpatched vulnerabilities for initial access.
  • Consider client-side monitoring/tamper-detection tooling that alerts on DOM or script changes to checkout flows.

Developing Story

Details on the specific AI agent frameworks, infrastructure, and compromise techniques involved have not been independently verified by df00tech and may evolve as more reporting emerges. This is net-new intelligence without an associated CVE. For the original reporting, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.