AI-Powered Cybercrime Campaign Steals 600K+ Credit Cards from Online Retailers
A financially motivated threat actor has leveraged autonomous AI agents to target hundreds of online retailers since July 2026, stealing over 600,000 unexpired credit card records in an ongoing campaign uncovered by Gambit Security. The operation, which remains active, automates vulnerability discovery, exploitation, data theft, and payment card skimming with some attacks including destructive cleanup actions that erase database tables or wipe payment fields post-exfiltration.
Attack Mechanics & AI Tools
The campaign employs three open-source AI agents:
- Strix: Conducts deep reconnaissance and vulnerability scanning.
- Cairn: Executes autonomous exploitation, securing shell or admin access over hours.
- Hermes: Orchestrates attacks, maintains persistence, and directs impact-stage actions.
A human operator, issuing brief prompts in Chinese, initiated attacks by directing agents to probe targets, validate exploits, and deploy JavaScript skimmers often by hijacking legitimate scripts, modifying Google Tag Manager, or poisoning cloud-hosted content. Between September 10–15, 2026, the actor launched 105 attack projects, compromising at least 27 organizations.
Cost & Scale
The operator used OpenRouter for AI model access, spending $7,005.71 over four weeks with estimated total campaign costs between $12,000–$18,000. The average cost per successful target was $25.46, though expenses ranged from $3.13 to $79.31 depending on the attack’s complexity.
Techniques & Impact
Beyond skimming, the threat actor employed destructive automation, including:
- Wiping Magento payment card fields after exfiltration.
- Deleting 180 database tables (including backups) via broad cleanup criteria.
The campaign highlights how AI-driven tools accelerate attacks, reducing the time between exposure and compromise while enabling a single operator to manage large-scale intrusions.
Indicators of Compromise (IoCs)
Gambit Security identified multiple IPs, domains, and skimmer payloads linked to the operation, including:
- Staging/C2 IPs:
155.254.22.215,209.126.4.170,213.21.239.62 - Skimmer hosts:
b8t[.]shop,cdn[.]netlfjs[.]com,x1opay[.]co - Proxy services: IPRoyal, 711proxy, 1024proxy
The full list of IoCs is available in the original report.
Source: https://gbhackers.com/autonomous-ai-agents-hack-online-retailers/
Magento TPRM report: https://www.rankiteo.com/company/adobe-commerce
Gambit Security TPRM report: https://www.rankiteo.com/company/gambitsecurity
"id": "gamado1790151984",
"linkid": "gambitsecurity, adobe-commerce",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '600,000+ (credit card holders)',
'industry': 'E-commerce, Retail',
'type': 'Online Retailers'}],
'attack_vector': 'Autonomous AI agents (Strix, Cairn, Hermes), JavaScript '
'skimmers, hijacking legitimate scripts (Google Tag Manager, '
'cloud-hosted content)',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '600,000+',
'personally_identifiable_information': 'Yes (credit card '
'numbers)',
'sensitivity_of_data': 'High (unexpired credit card details)',
'type_of_data_compromised': 'Payment card data (credit card '
'records)'},
'date_detected': '2026-09-10',
'description': 'A financially motivated threat actor has leveraged autonomous '
'AI agents to target hundreds of online retailers since July '
'2026, stealing over 600,000 unexpired credit card records in '
'an ongoing campaign uncovered by Gambit Security. The '
'operation automates vulnerability discovery, exploitation, '
'data theft, and payment card skimming, with some attacks '
'including destructive cleanup actions that erase database '
'tables or wipe payment fields post-exfiltration.',
'impact': {'data_compromised': '600,000+ unexpired credit card records',
'financial_loss': '$12,000–$18,000 (campaign costs)',
'identity_theft_risk': 'High (credit card data exposed)',
'operational_impact': 'Destructive actions (wiped database tables, '
'payment fields), compromised payment '
'processing',
'payment_information_risk': 'High (payment card skimming)',
'systems_affected': 'Online retail websites, databases, payment '
'systems'},
'initial_access_broker': {'entry_point': 'Vulnerability exploitation via AI '
'agents',
'high_value_targets': 'Online retailers with '
'payment systems'},
'investigation_status': 'Ongoing',
'lessons_learned': 'AI-driven tools accelerate attacks, reducing time between '
'exposure and compromise. Single operators can manage '
'large-scale intrusions with minimal effort.',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': 'Implement AI-resistant '
'security measures, enhance '
'script integrity '
'monitoring, enforce '
'database backup policies, '
'and deploy automated threat '
'detection for AI-driven '
'attacks.',
'root_causes': 'Automated AI-driven vulnerability '
'scanning and exploitation, lack of '
'robust script security (e.g., '
'Google Tag Manager hijacking), '
'insufficient database protections'},
'recommendations': 'Enhance monitoring for AI-driven reconnaissance, secure '
'legitimate scripts (e.g., Google Tag Manager), implement '
'database backup protections, and deploy behavioral WAFs '
'to detect automated exploitation.',
'references': [{'source': 'Gambit Security'}],
'response': {'third_party_assistance': 'Gambit Security (investigation)'},
'threat_actor': 'Financially motivated threat actor (Chinese-speaking '
'operator)',
'title': 'AI-Powered Cybercrime Campaign Steals 600K+ Credit Cards from '
'Online Retailers',
'type': 'Payment Card Skimming, Data Theft, Destructive Attack'}