• Latest
AI Agents Steal Over 600,000 Credit Cards in Autonomous Attacks on Retailers and Other Companies

AI Agents Steal Over 600,000 Credit Cards in Autonomous Attacks on Retailers and Other Companies

September 26, 2026
SoFi and Mastercard Go Live With Stablecoin Settlement

SoFi and Mastercard Go Live With Stablecoin Settlement

September 26, 2026
FTC Merchant-Screening Crackdown: Nuvei and Humboldt Cases Raise the Bar

FTC Merchant-Screening Crackdown: Nuvei and Humboldt Cases Raise the Bar

September 26, 2026
Amazon Expands UK BNPL with New Affirm Partnership

Amazon Expands UK BNPL with New Affirm Partnership

September 24, 2026
State Digital ID Systems to Fight Payment Fraud

Foster, Sessions Renew Push for Bill Funding State Digital ID Systems to Fight Payment Fraud

September 24, 2026
AI Agents Used to Run Autonomous Card-Skimming Campaign, 600K+ Cards Stolen

AI Agents Used to Run Autonomous Card-Skimming Campaign, 600K+ Cards Stolen

September 24, 2026
Romanian Crime Rings Exploit Magstripe EBT Cards for Large-Scale Fraud

Romanian Crime Rings Exploit Magstripe EBT Cards for Large-Scale Fraud

September 23, 2026
Walmart, Circle K Call Card Fee Pact Unconstitutional

Walmart, Circle K Call Card Fee Pact Unconstitutional

September 23, 2026
Banks Push for AI-Shopping Audit Trail as Chargeback Liability Fears Grow

Banks Push for AI-Shopping Audit Trail as Chargeback Liability Fears Grow

September 23, 2026
Dispute Management Explained: How Merchants Can Resolve Payment Disputes

Dispute Management Explained: How Merchants Can Resolve Payment Disputes

September 22, 2026
AI-Driven Attacks Set to Nearly Triple Global Banking Fraud by 2031

AI-Driven Attacks Set to Nearly Triple Global Banking Fraud by 2031

September 22, 2026
Third-Party App Breach Exposes Shopper Data at BigCommerce Merchants

Third-Party App Breach Exposes Shopper Data at BigCommerce Merchants

September 22, 2026
Mastercard Gives AI Agents a Virtual Card, but Shoppers Still Want the Final Click

Mastercard Gives AI Agents a Virtual Card, but Shoppers Still Want the Final Click

September 21, 2026
  • Contribute
  • Contact Us
  • About
  • Join Us
  • Advertise
Saturday, September 26, 2026
Merchant Fraud Journal
ADVERTISEMENT
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
Merchant Fraud Journal
No Result
View All Result

AI Agents Steal Over 600,000 Credit Cards in Autonomous Attacks on Retailers and Other Companies

By MFJ Staff | Sources: BleepingComputer, and Gambit Security

Key takeaway: Merchants and payment processors should treat this less as a one-off breach and more as a preview of how AI-orchestrated attacks will behave going forward. These attacks are fast, cheap, and adaptive to whatever access an agent manages to get. They can also survive initial cleanup attempts. One additional wrinkle Gambit flagged: the attacker’s own AI agent was instructed to wipe stolen card data from victim databases after exfiltration. This caused unrelated data loss at some retailers as a side effect. Breach response now needs to account for AI-driven cleanup routines destroying evidence or backups, not just the initial theft.

A financially motivated, apparently Chinese-speaking threat actor ran largely autonomous AI agents through an entire attack chain. Vulnerability scanning, exploitation, and campaign orchestration were all handled by AI. The target: online retailers and other companies at scale. The result: more than 600,000 valid credit card records stolen, according to research from cybersecurity firm Gambit Security reported by BleepingComputer.

The campaign has been running since at least July 2026 and was still active as of September 22. In a five-day window between September 10 and 15 alone, the attacker launched 105 distinct attack waves and compromised at least 27 companies to varying degrees, according to Gambit. Three open-source AI tools handled different stages of the attack. Strix ran vulnerability scanning. Cairn handled autonomous exploitation. Hermes managed orchestration and post-exploitation decisions. Hermes ran on Claude Opus 4.6, an older Anthropic model that Gambit says the operator turned to only after newer models refused its requests. It operated under a persona called “SOUL – Red Team Operator” with 121 built-in skills, 78 of them attack-related.

Gambit says it gained access to a staging server operated by the attacker, which let researchers reconstruct the campaign in detail. Of the 27 companies compromised in the September window, the attacker stole more than 600,000 valid card records from two of them and deployed card-skimming malware on five others. Across the broader campaign, Gambit found skimmers on at least 119 websites total. Named victims include a Fortune 500 hospitality company, a major U.S. airline, a large U.S. industrial supplies distributor, and an online fashion retailer. The human operator typed only short, high-level instructions in Chinese between autonomous runs: 1,951 prompts across 260 Hermes sessions. The agents carried out reconnaissance, exploitation, and exfiltration largely on their own. In some cases, they gained full access within hours.

Why it matters: This campaign shows autonomous AI agents now carrying out nearly every stage of a card-theft operation with minimal human direction. Gambit estimates the average cost at around $25 per target, ranging from $3.13 to $79.31 across 101 completed scans. That cost and skill floor makes large-scale carding operations newly accessible to less-sophisticated actors. Gambit also documented skimmer-persistence techniques, including cron jobs that automatically restored skimmers after removal. Remediation will likely be harder and slower than with traditional skimming malware.

Sources: BleepingComputer; Gambit Security

TweetShareSend
Previous Post

SoFi and Mastercard Go Live With Stablecoin Settlement

Search:

No Result
View All Result

Our Latest Reports

Fraud Trends Report

Consumer Payments Survey Report

Fraud Prevention Tactics that Enable Exceptional Customer Experience

ATO Fraud In Retail Report

3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue

Digital Trust And Safety Report: Combating the Evolving Complexities of Payment Fraud

On-Demand Webinars

New Trends in The Payments Ecosystem

Balancing Customer Experience and Fraud Prevention: What’s the Secret?

Stopping Fraud Across the Customer Lifecycle

Addressing Payment Fraud and the Customer Experience in 2022

 

Quick Navigation

  • Home
  • News
  • Join Us
  • About Us
  • Contact Us
  • Advertise
  • Contribute
  • Privacy Policy

Privacy Policy

Our Privacy Policy
Our Terms of Use

Resources

  • Articles
  • eCommerce Fraud Reports
  • eCommerce Fraud Webinars
  • Associations and Non-Profits
  • Podcasts
  • Vendor Directory
  • Chargeflow – AI Chargeback Management
No Result
View All Result
  • About Merchant Fraud Journal
    • Interested in Contributing or Guest Posting to Merchant Fraud Journal?
    • Merchant Fraud Journal Editorial Guidelines
  • Advertise on Merchant Fraud Journal
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Contact Us
  • Download Addressing Payment Fraud and Customer Experience Report
  • Download Chargebacks Consumer Survey Report 2022
  • Download Evolving Complexities of Payment Fraud Report
  • Download Fraud Prevention Tactics that Enable Exceptional Customer Experiences Report
  • Download Merchant Fraud Journal 2023 Fraud Trends Report
  • Download Merchant Fraud Journal 2024 Fraud Trends Report
  • Download Merchant Fraud Journal Generative AI Fraud Prevention Checklist for SMBs
  • Download Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
  • Download the 2020 Chargeback and Representment Report
  • Download the 2020 Merchant Fraud Journal Vendor Guide
  • Download the 2021 Fraud Trends Report
  • Download the 2022 Fraud Trends Report
  • Download the 2023 Consumer Payment Trends Report
  • Download the 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue Report
  • Download the MFJ 2022 Customer Experience Report
  • Download the MFJ ATO in Retail Report
  • Home
  • Home Elementor
  • Job Dashboard
  • Join The Merchant Fraud Journal Community
  • Merchant Fraud Journal Advertising Agreement
  • Merchant Fraud Journal Advertising Agreement – Signifyd
  • MFJ Fraud Trends Report Giveaway
  • News
  • Post a Job
  • Privacy Policy
  • Resources
    • #9978 (no title)
    • 2020 Chargeback Representment Guide for Merchants
    • 2020 Vendor Guide
    • 2023 Consumer Payments Survey Report
    • 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue
    • 8 Fraud Prevention Training and Certifications: A 2026 Guide
    • Addressing Payment Fraud and the Customer Experience in 2022
    • Associations and Non-Profits
    • ATO Fraud In Retail Report
    • Balancing Customer Experience and Fraud Prevention: What’s the Secret?
    • Chargebacks Consumer Survey Report 2022
    • Digital Trust & Safety: Combating the Evolving Complexities of Payment Fraud
    • eCommerce Fraud Reports
    • eCommerce Fraud Webinars
    • Fraud Prevention Tactics that Enable Exceptional Customer Experiences
    • How to Build a Recession Proof Chargeback Prevention Strategy
    • How to Reduce Customer Friction During Holiday Sales Season
    • How to Stop Fraud During the 2022 Holiday Season
    • Jobs Board
    • Merchant Fraud Journal 2023 Fraud Trends Report
    • Merchant Fraud Journal’s Fraud Trends 2020 Report
    • Merchant Fraud Journal’s Generative AI Fraud Prevention Report: A Checklist for SMB Companies
    • Merchant Fraud Journal’s Fraud Trends 2021 Report
    • Merchant Fraud Journal’s Fraud Trends 2022 Report
    • MFJ’s 2022 Customer Experience Report
    • Podcasts
    • Prevent High-Velocity Fraud Attacks During the 2021 Holiday Season
    • Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
    • Stopping Fraud Across the Customer Lifecycle
    • The surprisingly easy way to secure your payment data, reduce your risk, and win the war on ecommerce fraud
    • Vendor Directory
    • Webinar – Addressing Payment Fraud and the Customer Experience in 2022
    • Webinar – Mitigating Fraud and Risk on the ACH Network
    • Win January Chargeback Disputes
  • Subscribed
  • Terms and Conditions

© 2026 Merchant Fraud Journal

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?