According to BleepingComputer, a financially motivated threat actor has used open-source AI agent frameworks to attack online retailers at scale. The campaign resulted in the theft of more than 600,000 credit card records and the infection of over 100 websites with card skimmers.

The AI agents appear to have automated parts of the attack chain, allowing the operator to target hundreds of stores rather than manually compromising each one. The report does not name the specific frameworks or retailers involved.

This is the only source available for this story, so there is no independent confirmation of the details. The report does not mention any other campaigns or actors, and no differing claims were noted.