AI Skimmers on Online Shops: UAE Checkout Security Lessons
An autonomous AI campaign stole card data and planted skimmers across online shops. Here is what UAE ecommerce owners should check in checkout code, access and recovery.
An autonomous AI campaign stole card data and planted skimmers across online shops. Here is what UAE ecommerce owners should check in checkout code, access and recovery.

A financially motivated operator used three open-source AI tools to attack online retailers from July 2026 onwards. The tools searched for weaknesses, attempted exploitation, and managed follow-up tasks with very little human input. Between 10 and 15 September, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. (securityweek.com)
The campaign stole more than 600,000 unexpired card records from two companies. It also placed payment skimmers on five online shops. Gambit, the security firm that investigated the operation, said access often took less than a day and sometimes only a few hours. (gambit.security)
The UAE connection is direct, although it does not prove that UAE merchants were among the compromised businesses. Of the stolen cards that Gambit and its partner were able to classify, 13,559 were issued in the United Arab Emirates. That is enough to treat the report as relevant to local ecommerce operators rather than as a distant US incident. (gambit.security)
The important change is not that attackers now use AI. It is that a small team can probe more shops, more patiently and at lower cost.


A skimmer is malicious code that captures payment information during checkout. In this campaign, the code was hidden in several places: an existing JavaScript file, a script tag, a Google tag block, an AWS S3 bucket, database content, a Kubernetes deployment or a cached checkout page. (securityweek.com)
That matters because deleting one suspicious file may not remove the compromise. One retailer redeployed its application and restored a clean checkout bundle, but the attacker had left a scheduled task that checked the file and added the skimmer again when it disappeared. (gambit.security)
For a UAE shop, the practical risk is not limited to the server holding the website. It can include:
The report also describes data being erased after theft. In one case, an automated clean-up process removed backup tables among 180 dropped tables. A business that can restore only its database, but not its checkout, stock, order history and payment integrations, may still be unable to trade normally. (gambit.security)
The first step is to identify who can change the payment journey. Make a list of website administrators, hosting accounts, cloud storage, deployment tools, tag managers, plugins and third-party scripts. Remove old accounts, rotate credentials and require multi-factor authentication wherever the platform supports it.
Next, compare the checkout code with a known-clean version. Do not inspect only the visible page. Review loaded JavaScript, tag-manager rules, content security policy settings, cloud buckets, database content and cache layers. If the business uses a hosted ecommerce platform, ask the provider what it monitors and what evidence it can provide after a suspected compromise.
Then test whether a clean recovery is possible. Keep backups separate from the production account and confirm that the business can restore more than the database. The test should cover the storefront, order records, product data, payment connection, delivery workflow and customer communications.
A small retailer may not need a new security product immediately. It does need an owner who knows which supplier controls each part of checkout and how quickly a clean version can be put back online. If nobody can answer those questions, the gap is operational, not theoretical.
A rebuild is not automatically safer. Moving the same administrator accounts, plugins, scripts and cloud permissions into a new website can carry the weakness across. Start with a clean inventory and a reduced set of integrations. Add each payment, analytics and marketing script deliberately, with an owner and a reason.
For businesses launching or restructuring online sales, the UAE ecommerce setup guide for Amazon and Noon is relevant to the wider operating model, but it does not replace a technical security review. If the current site is difficult to maintain, a controlled rebuild may be sensible; Paknology’s websites and mobile apps service can help with the website work, but specialist cybersecurity support may still be needed for penetration testing, incident response or payment compliance.
Paknology has a commercial interest when this problem leads to a website rebuild, a new ecommerce launch or a change to the business’s digital setup. It does not provide a dedicated cybersecurity monitoring or incident-response service, so a cheaper or simpler option may be to ask the existing developer, hosting provider or payment partner to review the checkout first.
The sensible next step is to document every system that can alter checkout code, then arrange an independent security review if anything is unexplained. If the site itself needs rebuilding or its ecommerce setup needs restructuring, talk to Paknology with that inventory ready.
Sources
Book a free consultation and get a clear roadmap — from company formation to a fully automated digital operation.