AI agents automate attacks on hundreds of retailers

A financially motivated threat actor is running three largely autonomous AI harnesses against hundreds of online retailers, turning open-source tooling into a low-cost, scaled attack factory.[3][9][15] Researchers say the operation has been active since July 2026 and was still ongoing as of late September, with the systems working through tens of new targets every day.[1][3][9] The campaign, first detailed by Gambit Security and highlighted by SecurityWeek, underscores how quickly AI agents have moved from proof-of-concept to practical tooling in real-world intrusions.[1][3]

Gambit’s investigation of the attacker’s infrastructure shows that between 10 and 15 September alone, the operator launched 105 distinct “attack projects” and compromised at least 27 companies to varying degrees.[3][14][15] Victims during that burst included a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor, and a US fashion retailer, alongside smaller ecommerce brands.[11][14][15] From just two of the breached organizations, the attacker harvested data for more than 600,000 unexpired payment cards and quietly injected web skimmer code into numerous online storefronts to keep siphoning customer data over time.[1][9][13]

The operation is driven by three open-source AI harnesses that collectively automate most of the attack chain.[3][9][15] Strix, described as an AI-powered penetration testing framework, handles vulnerability discovery and scanning, running in a “deep mode” that Gambit recorded 146 times against 138 hosts for a total of 633 hours of scanner time.[3][15] Cairn acts as an autonomous exploitation engine, receiving target domains and goals such as obtaining a shell or administrative access, then iterating through probes and exploit attempts until it succeeds, times out, or is manually stopped.[3][9][15] Hermes sits atop both as an orchestration harness with persistent memory and a searchable archive of prior activity, loading a persona dubbed “SOUL – Red Team Operator” and dozens of attack-focused skills, including one explicitly designed to strip away its own content-security filters.[3][15]

Once Strix identifies a viable weakness in a retailer’s web stack, Cairn takes over to weaponize it, pivoting from initial access to deeper control of payment workflows and administrative interfaces.[3][9] From there, the attacker leverages Hermes to coordinate deployment of JavaScript payment-card skimmers and other data theft mechanisms across multiple sites, often in parallel.[1][9][13] Public reporting so far indicates that these AI agents can perform reconnaissance, exploitation, persistence, payment-data theft, and destructive cleanup with minimal human supervision, including wiping traces of the intrusion after exfiltration is complete.[9][15] Gambit’s cost analysis suggests the operator is spending on the order of tens of dollars per victim—about $25 per company—thanks to inexpensive infrastructure and reusable AI workflows.[3][11][14]

Researchers note that the disclosures to date focus on how autonomous agents are being chained together rather than on specific CVE identifiers or malware families, leaving many retailers to defend against a fast-moving, tooling-centric threat rather than a single signature.[1][3][9] For security teams, the campaign is a warning that commodity AI frameworks can now industrialize what used to be labor-intensive steps: vulnerability research, exploit development, campaign orchestration, and even post-compromise operations.[3][9][15] Online merchants that process card payments should tighten basic hygiene—keeping ecommerce platforms patched, enforcing strong authentication on admin portals, monitoring for unauthorized script changes, and aggressively tokenizing card data—and assume that well-resourced adversaries may already be experimenting with similar autonomous attack stacks.[9][15]

References

  1. AI-Powered Campaign Targets Hundreds of Online Retailers
  2. AI Agents Are Hacking Online Retailers for $25 a Company
  3. Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
  4. Fashion retailer: Autonomous AI Agents Hack Online Retailers …
  5. Autonomous AI Agents Steal 600,000 Payment Cards From …
  6. Gambit Security Unveils AI Agent Hacking Campaign
  7. Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply