Alleged China-Based Hackers Steal More Than 600K Payment Card Records

NEW YORK — A cybercriminal using artificial intelligence tools to attack online retailers has stolen more than 600,000 payment card records from two companies and placed card-stealing software on other shopping sites, according to research reported by BleepingComputer.

The campaign has operated since at least July and was still active as of Sept. 22, BleepingComputer reported, citing an investigation by cybersecurity company Gambit Security. Between Sept. 10 and 15, the attacker launched 105 attack projects and gained some degree of access at at least 27 companies, Gambit said. 

Numerous reports have stated the attackers are based in China.

The findings carry potential consequences for credit unions and other card issuers: Members’ cards can be exposed when they shop at a compromised retailer, even if the financial institution’s own systems have not been breached. Gambit said 488,372 of the stolen card records were issued in the United States. The researchers said they worked with a fraud specialist to handle the compromised records and notify issuers; they did not identify how many were credit union-issued cards. 

How the Campaign Worked

BleepingComputer said the attacker used three open-source AI frameworks to divide the work: Strix to scan for vulnerabilities, Cairn to pursue access to targeted systems and Hermes to coordinate the attacks and direct later activity. A human operator supplied brief instructions while the tools performed much of the work, according to Gambit. In one nine-day period in August, Strix ran 146 scans against 138 hosts. 

The attacker’s objectives included stealing card data already stored in retailers’ systems and installing skimmers — malicious code that captures payment information entered on checkout pages. Gambit said it confirmed skimmers on 19 named victims’ sites during the campaign and, with another researcher’s help, found more than 100 additional websites carrying a skimmer associated with it. That is a broader count than the five organizations for which Gambit described skimmer installations among its initially documented impacts. 

The malicious code reached checkout pages through several routes, including altered website files, inserted script tags, compromised content-delivery systems and changes to application deployments, BleepingComputer reported. Gambit said the targets included retailers as well as a major U.S. airline and a Fortune 500 hospitality company. The affected organizations were not named in the report. 

Theft Also Caused Data Loss

Gambit found instructions directing one AI agent to erase payment information from a retailer’s database after stealing it. The researchers said cleanup activity caused data loss at some victims, including one case in which the agent deleted backup tables along with its own temporary tables. 

The researchers estimated that operating the campaign cost $12,000 to $18,000. An attacker cost review found an average of $25.46 for each of 101 completed scans, Gambit said. The low cost and speed of the attacks could allow campaigns of this scale to be repeated, the researchers warned. Gambit described its findings as an interim assessment and said the full impact may be larger. 

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.