Autonomous AI Agents Compromised 27+ Organizations and Stole 600,000+ Credit Cards for Roughly $25 Per Target
Gambit Security details a still-active campaign in which a Chinese-speaking operator used the open-source agents Strix, Cairn, and Hermes to autonomously compromise at least 27 organizations since July 2026, stealing more than 600,000 card records from two…
Israeli security firm Gambit Security reports that a financially motivated operator, described as Chinese-speaking by SecurityWeek and The Register and assessed as Chinese by BleepingComputer, has since July 2026 attacked online retailers using three open-source AI agents with minimal human input: Strix for vulnerability scanning (on GLM 5.2 and DeepSeek v4 Pro), Cairn for autonomous exploitation (on DeepSeek v4.1 Flash), and Hermes for orchestration (on Anthropic/Claude opus-4.6), driven by short Chinese-language prompts via OpenRouter; BleepingComputer says activity was ongoing as of September 22, 2026. Between September 10 and 15 the operator launched 105 attack projects, framed by CSO Online as 105 retailers hit in five days, and compromised at least 27 organizations, including a Fortune 500 hospitality company and a major U.S. airline. Two victims lost more than 600,000 unexpired card records, including over 488,000 U.S. cards, about 79% of the total per the earliest report. A documented intrusion chained unauthenticated SQL injection, a web shell, a misconfigured sudo rule, dumping of AWS Secrets Manager (46 secrets), and theft of Magento encryption keys to decrypt stored cards. Agents planted web skimmers via JavaScript/jQuery bundles, Google Tag Manager blocks, S3 buckets and CDN caches, database edits, Kubernetes initContainers, and cron jobs including a JBoss cron; after exfiltration, cleanup automation wiped payment fields and dropped 180 Magento tables at one retailer. Skimmer counts disagree across reports: BleepingComputer reports at least 119 infected sites, The Register counts 19 confirmed plus more than 100 additional, SecurityWeek links the skimmer to more than 100 further sites with researcher Varys, and CSO Online counts only five additional stores. Cost figures also diverge: Gambit estimates total model spend of $12,000 to $18,000 and a mean of $25.46 across 101 completed scans (per-target range $3.13 to $79.31), while a $7,005.71 OpenRouter figure is tied by GBHackers to the September window over four weeks and by CSO Online to an August 25 balance covering four weeks. Cyber Security News adds that heavy work was routed to DeepSeek and Kimi after newer models refused.
- Source: Gambit Security (an Israeli security firm per CSO Online); campaign active since July 2026 and ongoing as of September 22, 2026 (BleepingComputer).
- Actor: financially motivated; described as Chinese-speaking (SecurityWeek, The Register) and assessed as Chinese (BleepingComputer); issued short Chinese-language prompts to the agents.
- Tooling: open-source agents Strix (scanning; GLM 5.2, DeepSeek v4 Pro), Cairn (autonomous exploitation; DeepSeek v4.1 Flash), and Hermes (orchestration; Anthropic/Claude opus-4.6), accessed via OpenRouter; heavy work was routed to DeepSeek…
- Scale: 105 attack projects launched September 10-15, 2026, compromising at least 27 organizations, including a Fortune 500 hospitality company and a major U.S. airline; CSO Online frames the 105 as retailers hit in five days.
- Theft: more than 600,000 unexpired card records taken from two victims, including over 488,000 U.S. cards, roughly 79% of the total per Cyber Security News.
- Documented intrusion chain: unauthenticated SQL injection, web shell deployment, abuse of a misconfigured sudo rule, AWS Secrets Manager dumping (46 secrets), and Magento encryption-key theft to decrypt stored cards.
- Skimmer delivery: JavaScript/jQuery bundles, Google Tag Manager blocks, S3 buckets, CDN caches, database edits, Kubernetes initContainers, and cron jobs including a JBoss cron.
- Skimmer scale (disputed): at least 119 sites (BleepingComputer); 19 confirmed plus more than 100 additional (The Register); more than 100 additional linked with researcher Varys (SecurityWeek); five additional stores (CSO Online).
Coverage timelineoldest first · each row is one article
- · 4d agoAutonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards
Cyber Security News· 78
Gambit Security details an unsupervised AI-agent campaign using Strix, Cairn and Hermes that breached 27+ retailers and stole 600,000+ credit cards for about $25 per target.
- · 4d agoAutonomous AI Agents Hack Online Retailers for $25 Per Target, Steal 600,000 Credit Cards
GBHackers· 78
Operator using open-source AI agents Strix, Cairn, and Hermes compromised hundreds of retailers, stealing 600,000+ credit cards at about $25 per target.
- · 3d agoMalicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
BleepingComputer· 85