By MFJ Staff | Sources: BleepingComputer, and Gambit Security
Key takeaway: Merchants and payment processors should treat this less as a one-off breach and more as a preview of how AI-orchestrated attacks will behave going forward. These attacks are fast, cheap, and adaptive to whatever access an agent manages to get. They can also survive initial cleanup attempts. One additional wrinkle Gambit flagged: the attacker’s own AI agent was instructed to wipe stolen card data from victim databases after exfiltration. This caused unrelated data loss at some retailers as a side effect. Breach response now needs to account for AI-driven cleanup routines destroying evidence or backups, not just the initial theft.
A financially motivated, apparently Chinese-speaking threat actor ran largely autonomous AI agents through an entire attack chain. Vulnerability scanning, exploitation, and campaign orchestration were all handled by AI. The target: online retailers and other companies at scale. The result: more than 600,000 valid credit card records stolen, according to research from cybersecurity firm Gambit Security reported by BleepingComputer.
The campaign has been running since at least July 2026 and was still active as of September 22. In a five-day window between September 10 and 15 alone, the attacker launched 105 distinct attack waves and compromised at least 27 companies to varying degrees, according to Gambit. Three open-source AI tools handled different stages of the attack. Strix ran vulnerability scanning. Cairn handled autonomous exploitation. Hermes managed orchestration and post-exploitation decisions. Hermes ran on Claude Opus 4.6, an older Anthropic model that Gambit says the operator turned to only after newer models refused its requests. It operated under a persona called “SOUL – Red Team Operator” with 121 built-in skills, 78 of them attack-related.
Gambit says it gained access to a staging server operated by the attacker, which let researchers reconstruct the campaign in detail. Of the 27 companies compromised in the September window, the attacker stole more than 600,000 valid card records from two of them and deployed card-skimming malware on five others. Across the broader campaign, Gambit found skimmers on at least 119 websites total. Named victims include a Fortune 500 hospitality company, a major U.S. airline, a large U.S. industrial supplies distributor, and an online fashion retailer. The human operator typed only short, high-level instructions in Chinese between autonomous runs: 1,951 prompts across 260 Hermes sessions. The agents carried out reconnaissance, exploitation, and exfiltration largely on their own. In some cases, they gained full access within hours.
Why it matters: This campaign shows autonomous AI agents now carrying out nearly every stage of a card-theft operation with minimal human direction. Gambit estimates the average cost at around $25 per target, ranging from $3.13 to $79.31 across 101 completed scans. That cost and skill floor makes large-scale carding operations newly accessible to less-sophisticated actors. Gambit also documented skimmer-persistence techniques, including cron jobs that automatically restored skimmers after removal. Remediation will likely be harder and slower than with traditional skimming malware.
Sources: BleepingComputer; Gambit Security












