AI Agents Are Becoming a New Weapon for Cybercrime

Automation is expanding the scale of digital theft.

Global

A cybercriminal used artificial intelligence agents to automate attacks against online businesses and compromise payment information on a scale that would have required far more manual effort only a few years ago. According to the investigation reported by Infobae, the campaign targeted e commerce environments with malicious programs designed to capture card data directly from compromised websites. Between September 10 and 15 alone, the agents launched 105 waves of attacks and affected 27 organizations to varying degrees.

The operation relied on skimmers, malicious code inserted into websites to intercept sensitive payment information as customers enter it. What makes the case distinctive is not the existence of this technique, which has been used for years, but the role assigned to artificial intelligence. Researchers were able to examine both the malicious programs and the instructions supplied by the attacker to the AI systems, revealing how autonomous agents were incorporated into the operational chain.

More than 600,000 payment card records were reportedly exposed or placed at risk during the broader campaign. The scale illustrates one of the most consequential changes emerging in cybersecurity: AI can reduce the amount of human labor required to coordinate reconnaissance, deployment and repeated attack attempts. A single operator may therefore be able to conduct activity across many targets with greater speed and persistence than traditional manual methods allowed.

The implications extend beyond financial theft. AI agents are designed to execute sequences of tasks, interact with tools and adapt their actions according to changing conditions. Those same capabilities that make them useful for legitimate business automation can also be exploited by malicious actors seeking to accelerate cyberattacks. The security problem is therefore shifting from defending against isolated malicious scripts toward defending against systems capable of orchestrating multiple steps with limited human intervention.

Organizations face a corresponding challenge. Traditional protections remain necessary, including secure code, continuous monitoring, rapid patching and payment infrastructure segmentation, but increasingly autonomous attacks may require equally automated defensive systems capable of detecting unusual behavior in real time. The competitive dynamic between attacker and defender is becoming faster and more machine driven.

The deeper lesson is that artificial intelligence does not create cybercrime from nothing. It changes its economics. When malicious activity becomes easier to scale, the cost of attacking falls while the potential reach expands.

Lo visible y lo oculto, en contexto. / The visible and the hidden, in context.

Related posts

Google Gives Enterprise AI a Face With Gemini Live Avatar

Google Takes AI Data Centers Beyond Earth

PPS Is Quietly Changing How Smartphones Manage Fast Charging