Advertisement

Dark web scammers leak 345,000 credit card records through vibe coding

A dark web marketplace selling stolen credit card data accidentally exposed more than 345,000 card records after relying heavily on AI coding tools to build its infrastructure. Researchers say the leak highlights the growing risks of “vibe coding”, where AI-generated software is deployed without proper security checks or human oversight.

Advertisement
Credit card scam due to vibe coding (Photo: Reuters)
Credit card scam due to vibe coding (Photo: Reuters)
FP Tech Desk|May 08, 2026, 12:42:43 IST

The same artificial intelligence tools helping startups build apps faster are now quietly reshaping cybercrime as well. But in one extraordinary twist, a dark web operation that relied heavily on AI-generated code ended up exposing itself through the very technology it trusted to automate its systems.

Researchers at Cybernews recently uncovered an unsecured server connected to “Jerry’s Store”, a criminal marketplace that allegedly sold stolen payment card information and offered customers tools to verify whether the cards still worked before purchasing them. The leak exposed around 345,000 payment card records, alongside internal systems, validation logs and administrative dashboards.

Advertisement

According to Cybernews, the exposure happened because the operators built large parts of their infrastructure using AI coding assistants but failed to properly secure what the tools generated.

The incident is now being viewed as one of the clearest examples yet of the risks associated with so-called “vibe coding”, an increasingly popular practice where users describe what they want in plain English while AI systems generate the code automatically.

techMore from Tech

How AI coding tools exposed the operation

The infrastructure behind Jerry’s Store was reportedly built using Cursor, an AI-powered coding assistant developed by US software company Anysphere. While Cursor itself is a legitimate development tool widely used by programmers, the operators allegedly depended on it heavily to create both their backend systems and internal staff dashboards.

According to Cybernews researchers, the problems began when vague instructions were given to the AI system without proper security checks afterwards.

Advertisement

What emerged was an exposed web dashboard accessible directly through a browser, with no password protection, login system or authentication barriers in place.

Cybernews discovered the server on April 16 and found that sensitive information had effectively been left open to the internet.

The leaked data included roughly 145,000 “valid” payment card records containing full card numbers, expiry dates, CVV security codes, names and billing addresses. Another 200,000 records had already been flagged by the system as invalid.

“The model behind Cursor, based on the logs, had enough context to know what it was helping with,” Cybernews noted. “A credit card verification service. It kept building anyway.”

How the card validation system worked

The exposed platform reportedly operated as a card verification service for criminals buying stolen payment details online.

Instead of blindly selling untested card data, the system checked whether cards were still active by conducting real-world payment tests through legitimate companies.

Researchers said the operators created fake accounts on platforms including Amazon, Grubhub, Sam’s Club, Temu, Lyft, Elf Cosmetics and CountryMax. The system would either attempt small transactions or add stolen cards as payment methods to test whether the cards remained functional.

Advertisement

Cards that successfully passed the checks were then marked as valid and sold at higher prices on dark web marketplaces.

On cybercrime forums, verified cards are considered significantly more valuable because untested card databases often contain expired or blocked information.

Cybernews traced the leak back to a single request inside the operators’ chat history with Cursor. One of the administrators reportedly asked the AI system to generate a statistics dashboard. The AI complied, but the resulting implementation was later deployed online without any security protections.

“While in this case it helped identify credit card fraud-related abuse, it’s also a lesson for developers using Cursor for legitimate uses, showing how it can lead to accidental data leaks,” Cybernews said.

Growing scrutiny over digital fraud and banking systems

The revelations come as regulators globally face mounting pressure over the rise of sophisticated online financial scams and digital fraud operations.

In India, the Reserve Bank of India recently directed five banks, Axis Bank, City Union Bank, ICICI Bank, IndusInd Bank and Yes Bank, to compensate a victim of a large-scale “digital arrest” scam.

According to reports, the RBI ombudsman ordered the banks to collectively pay Rs 1.31 crore after identifying failures linked to mule account monitoring and KYC compliance.

The case involves retired banker Naresh Malhotra, who claims fraudsters siphoned off nearly Rs 23 crore through an elaborate scam operation now under scrutiny in the Supreme Court of India.

Together, the two cases reveal a rapidly evolving cybercrime landscape where AI tools, weak security practices and gaps in financial oversight are increasingly colliding in dangerous ways.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:May 08, 2026, 12:42:43 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next