Hackers Stole 600,000 Credit Card Numbers Using AI
The attackers bypassed security safeguards by customizing open-source Chinese AI models.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you worry that the rapid growth of AI development makes your personal data less secure?
Hackers have successfully exfiltrated more than 600,000 credit card numbers from dozens of retailers. The unauthorized access was achieved by customizing open-source Chinese artificial intelligence models to circumvent the safeguards implemented by American AI firms.
Why it matters
This incident demonstrates a shift where sophisticated actors are leveraging open-source AI frameworks to automate cyberattacks against corporate infrastructure. The development highlights a emerging vulnerability where localized security controls are bypassed by adapted, non-proprietary models.
The attack involved the theft of 600,000 credentials from multiple retailers. The intrusion utilized open-source artificial intelligence models adapted to bypass conventional safety protocols established by American firms.
The players
American AI firms
Tech organizations focused on developing large-scale machine learning models and implementing safety protocols.
The details
Attackers bypassed security safeguards by modifying open-source Chinese artificial intelligence models. These models, which are software frameworks designed to simulate human-like reasoning, were repurposed to identify and exploit weaknesses in retailer data systems. By bypassing the safety parameters set by American AI firms, the attackers automated the extraction process across dozens of retail environments.
Timeline
September 2026: Reported date of the credit card theft.
The Tech Race
This incident mirrors the scale of the 2013 Target data breach while updating the method of attack to the modern era of automated intelligence. It highlights a critical escalation in the race between security safeguards and the weaponization of open-source artificial intelligence frameworks.
Retailers involved in the breach are expected to initiate notification processes for affected customers. Cardholders should monitor their statements for unauthorized transactions and remain alert for potential phishing attempts resulting from exposed personal data.
The takeaway
The use of customized open-source models signifies that AI-driven cyber threats are no longer theoretical and are capable of impacting large-scale commercial networks. Monitor official breach notifications from impacted retailers to determine if your financial information has been compromised.
Further reading
For more information on the evolving threat landscape, see the latest updates in Cybersecurity.
Source note: This article includes information reported by Bloomberg Business.
Live Poll
Do you worry that the rapid growth of AI development makes your personal data less secure?









