By MFJ Staff | Sources: Gambit Security, and Cyber Security News
Key takeaway: Merchants running card-not-present ecommerce should treat AI-accelerated, low-cost reconnaissance and exploitation as a near-term threat, not a future one. The campaign’s tempo, over 600 hours of scanner time compressed into 195 hours of clock time, outpaces detection and patching cycles built around human-speed attacks. Faster vulnerability remediation and skimmer-detection tooling are becoming urgent.
A financially motivated operator used three off-the-shelf, open-source AI agents to breach dozens of companies in a matter of days. The campaign stole more than 600,000 credit card records. Marginal cost per attack attempt averaged $25.46, according to research from Gambit Security.
Gambit Security’s Threat Intelligence team recovered the operator’s exposed staging server. From it, they reconstructed the campaign. It dates back to July 2026 and was still active at time of publication. The operator combined three tools: Strix for autonomous vulnerability discovery, Cairn for end-to-end exploitation, and Hermes to orchestrate the campaign and provide tactical guidance. Between Sept. 10 and 15 alone, Cairn launched 105 attack projects, compromising at least 27 companies to varying degrees.
Confirmed victims include a Fortune 500 hospitality firm, a major U.S. airline, a large industrial supplies distributor, and an online fashion retailer, with several additional retailers, including a storage retailer, a beauty retailer, and a wine retailer, hit separately through the skimmer campaign described below. Human involvement was minimal. Across 260 Hermes sessions, the operator typed only 1,951 commands, mostly short instructions in Chinese.
The economics are central to why researchers flagged the campaign. Between August and September 2026, the operator spent an estimated $12,000 to $18,000 on AI model access. That works out to a mean of $25.46 across 101 completed scans, ranging from roughly $3 to $79 each. It’s worth noting this figure is a cost-per-scan average, not a per-victim price tag; not every scan led to a successful breach, and the 600,000-plus stolen cards came from just two of the 27-plus compromised companies, not spread evenly across all of them.
One documented attack chain began with an unauthenticated SQL injection. The attacker used it to read a one-time password directly from the victim’s database, bypassing multi-factor authentication. From there, the operator escalated to root access and ultimately extracted the encryption key needed to decrypt stored card numbers from a Magento database. Anti-fraud firm Overwatch Data, which handled the stolen cards, found roughly 79% belonged to U.S. cardholders. Separately, the operator planted card-skimming scripts confirmed on 19 named victims and traced to more than 100 additional infected sites.
One claim needs a caveat: secondary coverage (Cyber Security News) reports that “a payment processor” confirmed at least 60% of a sampled batch of stolen cards had not previously been flagged for fraud. That detail doesn’t appear in Gambit Security’s own published research, and no processor is named. Treat it as an unconfirmed add from trade press, not a vendor-verified finding.
Why it matters: The campaign shows that autonomous AI agents can now run reconnaissance, exploitation, and data exfiltration against dozens of targets in parallel, with only minimal human direction. The cost is low enough to make previously unprofitable, low-value targets worth attacking. For merchants and payment processors, that shifts the fraud calculus. The population of companies worth targeting for a card-data breach just got much larger, because the attacker’s cost per attempt is now measured in dollars, not the time and skill of a dedicated human operator.
Sources: Gambit Security; Cyber Security News












