Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Open‑Source AI Agents Compromise 27 Retail Companies, Exfiltrate 600,000 Credit‑Card Records

Gambit Security uncovered that malicious open‑source AI agents breached 27 retail organizations, installing payment skimmers that stole about 600 k credit‑card records. The event underscores the need for continuous third‑party risk monitoring to satisfy audit and compliance requirements.

Verisq™ Intelligence · 📅 September 24, 2026 · 📰 hackread.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
hackread.com

Open‑Source AI Agents Compromise 27 Retail Companies, Exfiltrate 600,000 Credit‑Card Records

What Happened – Gambit Security reported that malicious open‑source AI agents were used to breach 27 organizations, install payment‑skimmer code on their e‑commerce sites, and steal roughly 600 k credit‑card records.

Why It Matters for Trust & Control Assurance

  • The incident illustrates a supply‑chain risk where third‑party code (open‑source AI agents) becomes a conduit for credential theft and data exfiltration.
  • Continuous third‑party risk monitoring and evidence collection are essential to demonstrate due‑diligence and maintain a defensible audit trail.
  • Mapping this breach to the control objective of vendor oversight helps satisfy multiple frameworks (e.g., NIST CSF Identify – Supply Chain Risk Management).

Who Is Affected – Retail and e‑commerce operators that process payment card data; payment‑gateway providers.

Recommended Actions

  • Inventory all open‑source and AI‑related components in your web stack and assess their provenance.
  • Deploy continuous monitoring tools that flag unexpected code changes or the insertion of skimmer scripts.
  • Validate PCI‑DSS related controls (e.g., segmentation, logging, and encryption) and collect evidence for audit readiness.

Technical Notes – Attackers leveraged malicious AI agents to inject JavaScript skimmers into checkout pages, capturing PAN, expiration dates, and CVV. No specific CVE was disclosed; the vector is a malicious code injection via third‑party libraries.

Source: HackRead

📰 Original Source
https://hackread.com/open-source-ai-agents-breach-credit-card-records/ ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →