By MFJ Staff | Source: BleepingComputer
Key takeaway: The campaign shows agentic AI collapsing both the cost and the skill floor for running skimming attacks at scale. It also introduces a new wrinkle for incident response: the attacker’s own cleanup routine can destroy the forensic and card data merchants need after a breach. Response plans built only around removing a skimmer may not account for data the attacker has already deliberately erased.
A financially motivated threat actor is using a chain of open-source AI agents to scan, exploit, and plant payment-card skimmers on online retailers at scale. The group has stolen more than 600,000 card records from just two of the businesses it hit, according to research from cybersecurity startup Gambit reported by BleepingComputer.
The campaign has been running since at least July and remains active as of September 22, 2026. In one five-day stretch, the attacker compromised at least 27 companies and launched more than 100 distinct attacks.
Gambit found the operation combines three AI tools into a single automated attack chain. Strix is an open-source penetration-testing framework used for scanning and vulnerability discovery. Cairn is an autonomous exploitation engine tasked with objectives like obtaining shell or admin access; it shares a name with, but is unrelated to, an AI malware-analysis tool Cisco Talos released the day before this report. Hermes is an orchestration agent that made tactical decisions and directed the other tools’ activity, reportedly steered using Anthropic’s claude-opus-4.6 model, according to a cited social media post. Strix alone ran 146 times against 138 hosts over one nine-day stretch, racking up 633 scanning hours, per Gambit’s data.
Gambit says it gained access to a staging server the attacker operated and used it to confirm the scope of the campaign directly. At least 119 websites were compromised with card skimmers, including a Fortune 500 hospitality company, a major U.S. airline, a large U.S. industrial-supplies distributor, and an online fashion retailer.
The skimmers were injected through methods that depended on the access the attacker gained. These included appending malicious code to legitimate JavaScript files, inserting script tags into checkout pages, poisoning CDN and server-side caches, and using cron jobs to automatically restore the skimmer if it was removed. Gambit also found that the attacker’s AI agent was instructed to wipe card data from compromised Magento databases after exfiltration. That cleanup step reportedly caused data loss and operational disruption at some victim retailers.
Why it matters: Gambit’s cost analysis is the detail merchants should pay closest attention to. An OpenRouter billing account the researchers accessed showed roughly $7,000 spent over about four weeks as of late August.
Based on subsequent activity, Gambit estimates total campaign costs of $12,000 to $18,000, averaging about $25 per targeted company. That kind of economics means a single operator with modest resources and short natural-language instructions can now run reconnaissance-to-exfiltration attacks against dozens of merchants a day, largely unattended. It’s a meaningful shift from the more manual, higher-cost skimming operations merchants have defended against historically.
Source: BleepingComputer












