Somewhere along the line someone is going to have a password that is their favorite sports team followed by their anniversary. Someone will reuse the same password over and over including a site with exploitable security flaws.
None of this is new, and none of this has destroyed the feasibility of electronic payments. AI has nothing to do with any of it.
The ability to conduct fraud, hack websites, and hijack accounts has always been around. The systems we've built will always assume that occurs on a regular basis, and are resilient against needing to address this reality. How does any of this prevent electronic payments from being processed?