Autonomous AI Agents Hack Online Retailers for $25 Per Target, Steal 600,000 Credit Cards
Operator using open-source AI agents Strix, Cairn, and Hermes compromised hundreds of retailers, stealing 600,000+ credit cards at about $25 per target.
Gambit Security uncovered an ongoing campaign, active since July 2026, in which a financially motivated operator used three open-source agents—Strix for reconnaissance, Cairn for autonomous exploitation, and Hermes for orchestration—to attack online retailers, stealing over 600,000 unexpired card records from two confirmed victims. Between September 10-15, 2026, the operator launched 105 attack projects and compromised at least 27 organizations, spending $7,005.71 via OpenRouter over four weeks with per-target costs of $3.13-$79.31. Web skimmers were injected via JavaScript bundles, Google Tag Manager blocks, database edits, and cloud content poisoning, followed by destructive cleanup including wiping payment fields and deleting 180 Magento tables. Operators issued brief Chinese-language prompts while agents autonomously performed scanning, exploitation, web-shell deployment, and data theft, with DNS exfiltration to staging infrastructure.