Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
An AI-agent campaign stole over 600,000 cards and skimmer-infected at least 119 retail sites.
Gambit reports a financially motivated operator, assessed as Chinese, has used open-source AI agent tools since at least July to compromise online retailers, with activity ongoing as of September 22. Strix performed vulnerability scanning, Cairn sought shells or admin access, and Hermes orchestrated post-exploitation with claude-opus-4.6. The actor stole more than 600,000 valid card records from two companies, planted skimmers on at least 119 sites, and hit organizations including a Fortune 500 hospitality firm and a major U.S. airline. Cleanup instructions that wiped Magento card fields after theft also caused data loss, while estimated model spend was about $12,000 to $18,000, roughly $25 per target.