Chinese AI models steal credit cards

Chinese AI models steal credit cards is the alarming shorthand for a campaign in which a Chinese-speaking human operator used artificial-intelligence agents to automate reconnaissance, vulnerability discovery, exploitation and payment-card theft against online retailers. Security researchers said more than 600,000 unexpired card records were exposed from two companies, including more than 488,000 U.S. cards. They observed 105 attack projects between September 10 and 15 and found at least 27 organizations compromised to varying degrees.
The wording needs precision. Researchers did not attribute the operation to the Chinese government, and the campaign was not autonomous in the sense of an AI acting without human direction. The operator used the Strix, Cairn and Hermes frameworks. Some tasks ran on Chinese-developed GLM and DeepSeek models, while Hermes also used Anthropic's Opus 4.6. The evidence supports a finding about a Chinese-speaking operator using a mixed model stack, not a claim that China or Chinese AI alone carried out the theft.
How the campaign worked
Agentic systems can chain steps that a human penetration tester would normally perform manually: enumerate a target, inspect software versions, test a suspected weakness, adapt after a failure and preserve notes for the next step. In this campaign, the operator created large numbers of discrete projects, allowing the systems to probe many e-commerce environments in parallel.
Once access was obtained, attackers could search for stored payment data or implant web skimmers that capture card details during checkout. Researchers linked skimmer infrastructure to more than 100 sites. That wider number does not mean every site suffered the same level of compromise; it describes associated infrastructure and observed exposure, while the confirmed organizational impact varied.
What the numbers mean
Scale came from automation, not a magical exploit
The 105 projects observed over six days show the operational advantage. Automation lowers the time required to discard unpromising targets and concentrate on vulnerable ones. It does not eliminate the need for exploitable software, exposed credentials or weak monitoring. The AI agents made existing security failures cheaper to find and reuse.
The cost figure changes attacker economics
Researchers estimated a mean model cost of $25.46 per target scan. That number is not the total cost of a criminal operation, which also includes infrastructure, operator time, laundering and the risk of detection. It does show that sophisticated-looking reconnaissance can be purchased for far less than the value of even a small number of valid cards.
More than 600,000 records sounds like 600,000 completed frauds, but it is not. The figure describes unexpired payment-card records exposed from two companies. Banks can cancel cards, fraud systems can block transactions and duplicate or stale records can reduce criminal value. The breach is still serious because card replacement, customer notification and incident response impose large costs even when attempted fraud is stopped.
Why retailers are exposed
Online merchants often depend on a dense stack of storefront software, plug-ins, payment integrations, analytics scripts and third-party services. A single outdated component can become an entry point. Smaller retailers may lack round-the-clock security monitoring, while larger companies can struggle to inventory every internet-facing system after acquisitions or rapid growth.
AI agents amplify this asymmetry. Defenders must secure every reachable path; an attacker needs one reusable weakness. The models also preserve context and generate code quickly, allowing a modestly skilled operator to run more experiments. Human judgment still matters, but the productivity threshold for a broad campaign is falling.
Who wins and who loses
Criminal operators gain speed and lower reconnaissance costs. Providers of stolen-card marketplaces and laundering services can benefit downstream. Consumers, merchants and banks absorb the losses through fraud, replacement cards, investigations and higher compliance costs. AI vendors also face pressure to improve abuse monitoring without blocking legitimate security research.
Defenders are not powerless. The same automation can help inventory assets, prioritize patches, compare checkout scripts against known-good versions and investigate alerts. The organizations best positioned are those that combine rapid technical controls with clear authority to take a payment page offline when tampering is suspected.
What companies should do next
Retailers should patch internet-facing systems, rotate exposed credentials, enforce phishing-resistant multifactor authentication for administrators and monitor checkout code for unauthorized changes. Payment-card data should be minimized and tokenized so a web-server compromise does not automatically expose reusable card numbers. Logs need to be retained long enough to reconstruct an intrusion that may have begun weeks before discovery.
The strategic lesson is broader than this campaign. Security teams should assume attackers can now test many hypotheses cheaply and continuously. Defenses built around a human attacker's limited time are becoming obsolete. Fast asset discovery, automatic containment and payment-page integrity checks are the counterweight.