Magento and Gambit Security: Autonomous AI Agents Hack Online Retailers for $25 Per Target, Steal 600,000 Credit Cards

Magento and Gambit Security: Autonomous AI Agents Hack Online Retailers for $25 Per Target, Steal 600,000 Credit Cards

AI-Powered Cybercrime Campaign Steals 600K+ Credit Cards from Online Retailers

A financially motivated threat actor has leveraged autonomous AI agents to target hundreds of online retailers since July 2026, stealing over 600,000 unexpired credit card records in an ongoing campaign uncovered by Gambit Security. The operation, which remains active, automates vulnerability discovery, exploitation, data theft, and payment card skimming with some attacks including destructive cleanup actions that erase database tables or wipe payment fields post-exfiltration.

Attack Mechanics & AI Tools

The campaign employs three open-source AI agents:

  • Strix: Conducts deep reconnaissance and vulnerability scanning.
  • Cairn: Executes autonomous exploitation, securing shell or admin access over hours.
  • Hermes: Orchestrates attacks, maintains persistence, and directs impact-stage actions.

A human operator, issuing brief prompts in Chinese, initiated attacks by directing agents to probe targets, validate exploits, and deploy JavaScript skimmers often by hijacking legitimate scripts, modifying Google Tag Manager, or poisoning cloud-hosted content. Between September 10–15, 2026, the actor launched 105 attack projects, compromising at least 27 organizations.

Cost & Scale

The operator used OpenRouter for AI model access, spending $7,005.71 over four weeks with estimated total campaign costs between $12,000–$18,000. The average cost per successful target was $25.46, though expenses ranged from $3.13 to $79.31 depending on the attack’s complexity.

Techniques & Impact

Beyond skimming, the threat actor employed destructive automation, including:

  • Wiping Magento payment card fields after exfiltration.
  • Deleting 180 database tables (including backups) via broad cleanup criteria.

The campaign highlights how AI-driven tools accelerate attacks, reducing the time between exposure and compromise while enabling a single operator to manage large-scale intrusions.

Indicators of Compromise (IoCs)

Gambit Security identified multiple IPs, domains, and skimmer payloads linked to the operation, including:

  • Staging/C2 IPs: 155.254.22.215, 209.126.4.170, 213.21.239.62
  • Skimmer hosts: b8t[.]shop, cdn[.]netlfjs[.]com, x1opay[.]co
  • Proxy services: IPRoyal, 711proxy, 1024proxy

The full list of IoCs is available in the original report.

Source: https://gbhackers.com/autonomous-ai-agents-hack-online-retailers/

Magento TPRM report: https://www.rankiteo.com/company/adobe-commerce

Gambit Security TPRM report: https://www.rankiteo.com/company/gambitsecurity

"id": "gamado1790151984",
"linkid": "gambitsecurity, adobe-commerce",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '600,000+ (credit card holders)',
                        'industry': 'E-commerce, Retail',
                        'type': 'Online Retailers'}],
 'attack_vector': 'Autonomous AI agents (Strix, Cairn, Hermes), JavaScript '
                  'skimmers, hijacking legitimate scripts (Google Tag Manager, '
                  'cloud-hosted content)',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '600,000+',
                 'personally_identifiable_information': 'Yes (credit card '
                                                        'numbers)',
                 'sensitivity_of_data': 'High (unexpired credit card details)',
                 'type_of_data_compromised': 'Payment card data (credit card '
                                             'records)'},
 'date_detected': '2026-09-10',
 'description': 'A financially motivated threat actor has leveraged autonomous '
                'AI agents to target hundreds of online retailers since July '
                '2026, stealing over 600,000 unexpired credit card records in '
                'an ongoing campaign uncovered by Gambit Security. The '
                'operation automates vulnerability discovery, exploitation, '
                'data theft, and payment card skimming, with some attacks '
                'including destructive cleanup actions that erase database '
                'tables or wipe payment fields post-exfiltration.',
 'impact': {'data_compromised': '600,000+ unexpired credit card records',
            'financial_loss': '$12,000–$18,000 (campaign costs)',
            'identity_theft_risk': 'High (credit card data exposed)',
            'operational_impact': 'Destructive actions (wiped database tables, '
                                  'payment fields), compromised payment '
                                  'processing',
            'payment_information_risk': 'High (payment card skimming)',
            'systems_affected': 'Online retail websites, databases, payment '
                                'systems'},
 'initial_access_broker': {'entry_point': 'Vulnerability exploitation via AI '
                                          'agents',
                           'high_value_targets': 'Online retailers with '
                                                 'payment systems'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'AI-driven tools accelerate attacks, reducing time between '
                    'exposure and compromise. Single operators can manage '
                    'large-scale intrusions with minimal effort.',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'corrective_actions': 'Implement AI-resistant '
                                                  'security measures, enhance '
                                                  'script integrity '
                                                  'monitoring, enforce '
                                                  'database backup policies, '
                                                  'and deploy automated threat '
                                                  'detection for AI-driven '
                                                  'attacks.',
                            'root_causes': 'Automated AI-driven vulnerability '
                                           'scanning and exploitation, lack of '
                                           'robust script security (e.g., '
                                           'Google Tag Manager hijacking), '
                                           'insufficient database protections'},
 'recommendations': 'Enhance monitoring for AI-driven reconnaissance, secure '
                    'legitimate scripts (e.g., Google Tag Manager), implement '
                    'database backup protections, and deploy behavioral WAFs '
                    'to detect automated exploitation.',
 'references': [{'source': 'Gambit Security'}],
 'response': {'third_party_assistance': 'Gambit Security (investigation)'},
 'threat_actor': 'Financially motivated threat actor (Chinese-speaking '
                 'operator)',
 'title': 'AI-Powered Cybercrime Campaign Steals 600K+ Credit Cards from '
          'Online Retailers',
 'type': 'Payment Card Skimming, Data Theft, Destructive Attack'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.