Trusence Technology, daily
Last updated 24 September 2026 Türkçe
← All stories
Security

AI-powered campaign steals 600,000+ card records, hits 119 retail sites

An automated toolchain lets one actor run hundreds of low-cost attacks on online retailers, stealing payment data and erasing some of it from merchant systems.

Cybersecurity firm Gambit has detailed an ongoing campaign where a financially motivated actor uses open‑source AI agent frameworks to attack online retailers at scale, stealing over 600,000 credit card records. The operation chains three tools — Strix for scanning, Cairn for autonomous exploitation, and Hermes for orchestration driven by Claude Opus 4.6 — to launch hundreds of largely automated attacks, including 105 attack waves against at least 27 companies in mid‑September alone. Gambit reports at least 119 websites had credit card skimmers implanted, with victims including multiple large U.S. enterprises across hospitality, aviation, industrial supply, and fashion retail. The attacker spends an estimated $12,000–$18,000 on API usage, translating to roughly $25 per targeted company, enabling low‑cost, repeatable compromise where AI agents work mostly from brief human instructions. In some cases, the AI‑driven cleanup phase wiped card data from Magento databases after exfiltration, causing data loss and operational issues for affected merchants, which Gambit highlights as an additional risk for defenders to plan for.

Why it matters

Gambit’s findings show how a single operator can scale attacks on online retailers by chaining open-source AI agents into a largely automated pipeline. The tooling lets the actor scan and rank targets, compromise at least 27 companies in a few days, and plant skimmers on 119 sites, including major brands in sectors that depend on online bookings and orders. By instructing agents to wipe Magento card data after exfiltration, the campaign not only steals payment details but also corrupts merchants’ own records, creating an extra layer of operational risk.

Sources