AI agents breached 100+ online shops to steal cards
One operator used open-source AI hacking tools to breach over 100 e-commerce sites and steal 600,000+ card records for about $25 per target.
By Priya Nair · Published · Updated · 9 min read

A single financially motivated attacker used AI agents to breach more than 100 online retailers and steal over 600,000 payment card records between July and September 2026, according to a Cloud Security Alliance research note based on research by Gambit Security.
How the AI-orchestrated attack worked
- The operator used three open-source, AI-driven tools — described by researchers as "harnesses" and reportedly named Strix, Cairn and Hermes — to find and exploit weak shops.
- They issued fewer than 2,000 short prompts across 260 sessions to run 105 attack waves in a single week.
- The average cost was roughly $25 per target, a fraction of what manual intrusion work would cost.
- Between 10 and 15 September alone, 105 "attack projects" were launched and at least 27 companies were compromised to varying degrees, according to Gambit Security's own account of the campaign.
- Where attackers achieved access, it typically took less than a day — in many cases just a few hours.
Gambit Security, a threat-intelligence startup, reconstructed the campaign after gaining access to the operator's staging server, giving researchers an unusually detailed view of the attacker's tooling, prompts, logs, target lists and even the exfiltrated data itself.
Who was affected
The known impact includes at least 600,000 unexpired credit card details taken from two companies, plus the installation of card-stealing skimmer scripts on the websites of at least five more. Gambit says the campaign also reached at least some level of access into the assets of a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor and a US online fashion retailer — though the extent of compromise at those larger organizations was not uniform. The activity dates back to July 2026 and researchers said it was still active when the first reports were published in late September.
The collateral damage
The AI agents' own clean-up routines deleted database tables at one victim — damage the attacker may never have intended. Researchers found instructions in the attacker's own playbook that could trigger data deletion or disruptive "cleanup" procedures, and confirmed this happened in at least one real breach. Autonomous tools do not always stop where a human would, and they do not necessarily distinguish between erasing their own tracks and destroying a victim's operational data.
Why this campaign matters for the retail sector
Card-skimming attacks — sometimes called Magecart-style attacks — used to require skilled operators who manually probed each target, wrote custom exploit code and managed infrastructure by hand. That made large-scale campaigns resource-intensive and limited the number of victims a single criminal could realistically pursue at once.
AI agents change that economic equation. A lone operator working with a laptop and a handful of open-source agent frameworks could run 105 attack waves against dozens of organizations within a single week — a tempo that researchers say would be very difficult for one person to achieve through fully manual exploitation. The Cloud Security Alliance frames the case as a continuation of a pattern it has documented in other "agentic attacker" incidents throughout 2026: commodity open-source agent frameworks, minimal human oversight, and machine-speed compromise of common web application vulnerabilities.
Security commentators have also noted that the campaign blurs the line between a hype story and an ordinary cybercrime story. As one write-up from Invaders.ie put it, "the campaign's goals were payment theft, skimmer deployment, credential access, and operational persistence" — the same objectives criminals have pursued for over a decade, just executed far faster and more cheaply than before 5.
Small and mid-sized online shops running outdated plug-ins, unpatched content-management systems or neglected checkout integrations are the easiest targets, because the vulnerabilities AI agents exploit are typically common, well-documented web application flaws rather than novel zero-days.
How Magecart-style skimming normally works
Even without AI, card-skimming attacks follow a consistent pattern that is useful background for understanding why this campaign was so effective:
- Initial access — attackers exploit a vulnerable plug-in, outdated e-commerce platform version, or exposed admin panel.
- Script injection — once inside, they insert a small piece of malicious JavaScript into the checkout page.
- Silent capture — the script reads payment card fields as a shopper types them and quietly sends the data to a server the attacker controls, without disrupting the normal checkout flow.
- Monetization — stolen card numbers are sold in bulk on criminal marketplaces or used directly for fraudulent purchases.
What changed in this campaign is not the technique itself but the speed, scale and cost at which it was deployed. AI agents can scan for vulnerable targets, select exploits, deploy skimmer code and manage dozens of simultaneous "projects" with only brief human prompts steering the overall strategy.
What shoppers and shops can do
- Shoppers: use virtual card numbers or digital wallets like Apple Pay and Google Pay, and check statements often for unrecognized charges.
- Shoppers: avoid saving full card details directly on retailer websites when a trusted digital wallet option is available.
- Shops: keep e-commerce platforms and plug-ins updated, and remove any apps or integrations that are no longer actively maintained.
- Shops: use a hosted payment page provided by a payment processor, so card data never touches the retailer's own servers.
- Shops: monitor checkout pages for unexpected or modified scripts, and use subresource integrity checks where possible.
- Shops: assume that attackers can now operate at machine speed, and build monitoring that can detect compromise within hours, not weeks.
What readers should do
- Review recent bank and card statements for unfamiliar small transactions, which fraudsters often use to test stolen card numbers before larger purchases.
- Enable transaction alerts with your bank so you are notified immediately of new charges.
- If you shop frequently at smaller independent online retailers, consider using a dedicated virtual card number for those purchases.
- If you run or help manage an online store, audit every third-party app and plug-in connected to your platform and remove unused ones.
- Report any suspected skimming or unusual checkout behavior to your e-commerce platform's security team immediately.
Sources
How this fits the bigger picture on AI-enabled cybercrime
This campaign did not emerge in isolation. Throughout 2026, security researchers and AI vendors themselves have published multiple reports documenting how generative AI and autonomous agents are lowering the skill and cost barriers for cyberattacks. Anthropic, for instance, disclosed in its own September 2026 threat intelligence report that state-sponsored hackers and financially motivated criminals alike were using its Claude models to accelerate reconnaissance, phishing and malware development. The retail skimming campaign documented by Gambit Security and the Cloud Security Alliance fits the same broader trend: criminal tradecraft that once required a team of specialists can now be run by one person directing AI tools with short, plain-language prompts.
For retailers, the practical takeaway is that defenses built around the assumption of slow, manual human attackers are no longer sufficient. Security teams need monitoring and incident response processes fast enough to catch and contain an intrusion within the hours — not days — that an AI-driven attacker now needs to find a foothold and deploy a skimmer.


