AI‑Powered Agents Compromise 100+ E‑Commerce Sites, Steal 600K Credit Cards via Skimmer Injection
What Happened — A financially motivated threat actor leveraged open‑source AI agent frameworks (Strix, Cairn, Hermes) to scan, exploit, and inject malicious skimmer code into more than 100 online retail sites. Over a five‑day window the campaign exfiltrated more than 600,000 valid credit‑card records and left persistent skimmers on at least 119 compromised domains.
Why It Matters for Trust & Control Assurance
- Demonstrates how automated, AI‑driven exploitation can bypass traditional point‑in‑time vulnerability scans, highlighting the need for continuous control monitoring and evidence of remediation.
- Shows that insecure code‑deployment pipelines and mis‑configured web assets become a single point of failure across many frameworks (PCI DSS, NIST CSF, ISO 27001).
- Aligns directly with Verisq’s Control Mapping capability, which provides ongoing, framework‑agnostic evidence that configuration and code‑integrity controls are operating as intended.
Who Is Affected
- Retail & e‑commerce operators handling payment data.
- Hospitality, airline, and industrial‑supply firms with public‑facing web applications.
Recommended Actions
- Map your web‑application security controls (code‑integrity, configuration management, runtime monitoring) to the VCF control objective “Secure configuration and code integrity.”
- Deploy continuous evidence collection for deployment pipelines and web‑asset inventories; validate that changes are logged and approved.
- Conduct a rapid forensic sweep of all web servers, CDNs, and container orchestration layers for unauthorized script injections.
- Refresh incident‑response playbooks to include AI‑agent‑driven exploitation scenarios.
Source: BleepingComputer
Technical Notes
- Attack vector: AI‑orchestrated vulnerability exploitation → malicious JavaScript/skimmer injection via compromised build pipelines, Kubernetes deployments, S3/CDN caches, and cron jobs.
- Tools: Strix (automated scanning), Cairn (autonomous exploitation), Hermes (orchestration using Claude‑Opus‑4.6).
- Data types: Full PAN, expiration dates, CVV – PCI‑DSS scope.
Source: BleepingComputer