AI-Powered Cyberattack Campaign Targets Retailers, Steals 600K+ Payment Records
A financially motivated threat actor has leveraged three open-source AI tools Strix, Cairn, and Hermes to conduct low-cost, automated cyberattacks against businesses, primarily online retailers. Research by Gambit Security, shared with Hackread.com, uncovered an exposed staging server revealing the campaign, active since July 2026, with attacks costing as little as $3.13 per target and averaging $25.46 across 101 scans.
Between September 10 and 15, the operator launched 105 attack projects, compromising at least 27 companies, including a Fortune 500 hospitality firm, a major US airline, an online fashion retailer, and a large industrial supplies distributor. The AI-driven pipeline required minimal human oversight, with the operator issuing just 1,951 short commands in Chinese across 260 sessions.
The attack chain relied on Strix for vulnerability discovery (running 146 deep scans in 195 hours), Cairn for autonomous exploitation, and Hermes as the central orchestrator loaded with a "Red Team Operator" persona and 78 attack skills, including one to bypass content-security filters. In one case, the AI exploited an SQL injection, obtained a plaintext one-time password, uploaded a web shell, escalated privileges via a misconfigured sudo rule, and accessed AWS credentials.
The campaign resulted in the theft of over 600,000 unexpired credit card records from two companies and the deployment of skimmers on at least 19 websites, with malicious scripts confirmed on 100+ additional sites. Attackers used multiple infection vectors, including poisoning AWS S3 content, modifying database entries, and hijacking legitimate JavaScript libraries. At one US wine retailer, a cron job persistently reinfected files every two minutes after cleanup attempts.
Beyond data theft, the operation caused destructive damage. A "Database Wipe After Extraction" skill instructed Hermes to purge payment data from Magento databases post-exfiltration. At a bicycle retailer, an automated routine dropped 180 tables, including backups, disrupting recovery efforts.
Gambit Security collaborated with the Shadowserver Foundation and industry partners to notify victims and dismantle associated infrastructure. The campaign demonstrates how open-source AI agents can now execute reconnaissance, exploitation, persistence, and destructive cleanup with minimal human intervention, posing a significant challenge to traditional cybersecurity defenses.
Source: https://hackread.com/open-source-ai-agents-breach-credit-card-records/
Major US airline TPRM report: https://www.rankiteo.com/company/united-airlines
"id": "uni1790188403",
"linkid": "united-airlines",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Hospitality',
'location': 'US',
'name': 'Fortune 500 hospitality firm',
'size': 'Large',
'type': 'Hospitality'},
{'industry': 'Transportation',
'location': 'US',
'name': 'Major US airline',
'size': 'Large',
'type': 'Airline'},
{'industry': 'Retail/Fashion',
'name': 'Online fashion retailer',
'size': 'Large',
'type': 'E-commerce'},
{'industry': 'Industrial Supplies',
'name': 'Large industrial supplies distributor',
'size': 'Large',
'type': 'E-commerce/Distribution'},
{'industry': 'Retail/Alcohol',
'location': 'US',
'name': 'US wine retailer',
'type': 'E-commerce'},
{'industry': 'Retail/Sports',
'name': 'Bicycle retailer',
'type': 'E-commerce'}],
'attack_vector': ['SQL injection',
'AWS S3 poisoning',
'JavaScript library hijacking',
'cron job persistence',
'misconfigured sudo rules'],
'data_breach': {'data_exfiltration': 'Yes (600K+ records stolen)',
'file_types_exposed': ['Database entries', 'JavaScript files'],
'number_of_records_exposed': '600,000+',
'personally_identifiable_information': 'Yes (payment records, '
'PII)',
'sensitivity_of_data': 'High (unexpired credit card records, '
'PII)',
'type_of_data_compromised': ['Payment records',
'credit card information',
'personally identifiable '
'information (PII)']},
'date_detected': '2026-07-01',
'description': 'A financially motivated threat actor leveraged three '
'open-source AI tools (Strix, Cairn, and Hermes) to conduct '
'low-cost, automated cyberattacks against businesses, '
'primarily online retailers. The campaign resulted in the '
'theft of over 600,000 unexpired credit card records and the '
'deployment of skimmers on at least 19 websites. The attack '
'chain involved vulnerability discovery, autonomous '
'exploitation, and destructive data wiping with minimal human '
'oversight.',
'impact': {'brand_reputation_impact': 'High (data breach, skimmer deployment, '
'destructive actions)',
'data_compromised': 'Over 600,000 unexpired credit card records, '
'payment data, PII',
'identity_theft_risk': 'High (600K+ payment records exposed)',
'operational_impact': 'Disrupted recovery efforts due to '
'destructive data wiping, persistent '
'reinfection via cron jobs',
'payment_information_risk': 'High (credit card skimming, unexpired '
'records stolen)',
'systems_affected': ['e-commerce websites',
'AWS environments',
'Magento databases',
'JavaScript libraries']},
'initial_access_broker': {'backdoors_established': 'Web shells, cron job '
'persistence',
'entry_point': ['SQL injection',
'AWS S3 poisoning',
'JavaScript library hijacking'],
'high_value_targets': ['AWS credentials',
'Magento databases',
'payment systems'],
'reconnaissance_period': '195 hours (146 deep '
'scans)'},
'investigation_status': 'Ongoing (infrastructure dismantled, victims '
'notified)',
'lessons_learned': 'Open-source AI tools can now automate complex attack '
'chains (reconnaissance, exploitation, persistence, and '
'destructive cleanup) with minimal human intervention, '
'posing significant challenges to traditional '
'cybersecurity defenses.',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': ['Dismantle malicious '
'infrastructure',
'Notify victims and assist '
'in cleanup',
'Collaborate with industry '
'partners to improve '
'defenses against AI-driven '
'threats'],
'root_causes': ['AI-driven automation enabling '
'low-cost, scalable attacks',
'Exploitation of known '
'vulnerabilities (SQLi, '
'misconfigured sudo rules)',
'Poorly secured AWS credentials '
'and third-party dependencies',
'Lack of real-time monitoring for '
'AI-driven attack patterns']},
'ransomware': {'data_exfiltration': 'Yes (600K+ records exfiltrated)'},
'recommendations': ['Enhance monitoring for AI-driven attack patterns',
'Implement stricter access controls for AWS credentials '
'and sudo rules',
'Regularly audit JavaScript libraries and third-party '
'dependencies',
'Deploy behavioral WAFs and adaptive security measures',
'Improve database backup and recovery procedures to '
'mitigate destructive attacks'],
'references': [{'source': 'Gambit Security (via Hackread.com)'},
{'source': 'Shadowserver Foundation'}],
'regulatory_compliance': {'regulations_violated': ['PCI DSS (Payment Card '
'Industry Data Security '
'Standard)']},
'response': {'remediation_measures': 'Infrastructure dismantling, victim '
'notifications, cleanup of malicious '
'scripts',
'third_party_assistance': 'Gambit Security, Shadowserver '
'Foundation, industry partners'},
'threat_actor': 'Financially motivated threat actor (Chinese-speaking '
'operator)',
'title': 'AI-Powered Cyberattack Campaign Targets Retailers, Steals 600K+ '
'Payment Records',
'type': 'AI-driven cyberattack, data breach, ransomware-like destructive '
'actions',
'vulnerability_exploited': ['SQL injection',
'misconfigured sudo rules',
'AWS credential exposure',
'Magento database vulnerabilities']}