Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 7/10

AI Agents Take Down Hundreds of Online Stores: 600,000 Credit Card Records Stolen

An attacker used autonomous AI agents to automatically attack online stores and steal credit card data. Analysts reconstructed the campaign.

What happened?

IT security researchers at the company Gambit Security have uncovered an attack campaign in which a malicious actor used AI agents to automatically attack hundreds of online stores. Between September 10 and 15 of this year, the attacker reportedly launched 105 attack projects, of which at least 27 companies were compromised to varying degrees. The activities can be traced back to July 2026 and, according to the analysts, are still ongoing.

The researchers managed to gain access to the attacker's staging server and reconstruct the campaign from it. They do not explain exactly how this access was obtained. Anthropic identified and blocked the account used, while Cloudflare stated it had shut down the attacker's infrastructure — however, the attacker quickly set up new servers.

The Details

The attacks ran largely autonomously via AI agents that targeted dozens of companies per day. According to the analysts, data from at least 600,000 not-yet-expired credit cards was copied from two companies. At five additional companies, the AI agents installed skimmer scripts that capture credit card data directly during the checkout process.

Affected organizations include a Fortune 500 hospitality company, a major US airline, a large US industrial supply distributor, and a US online fashion retailer. Once the attackers gained access, they typically needed less than a day — often just a few hours — to complete the attack.

For their analysis, the researchers relied on three sources: the exfiltrated data and associated tools found on the staging server, comparisons with compromised systems in the wild, and logs and statements from the AI systems used themselves. Where independent verification was not possible, the researchers treated the AI's statements as accurate provided that log files of the exploit processes documented success. The analysis is not yet complete, and individual errors are possible — the researchers estimate the actual scale of the campaign to be larger than what has been documented so far.

Three open-source AI agents were deployed with clearly divided roles: Strix for vulnerability discovery, Cairn for automated attacks and exploits, and Hermes for controlling and managing the overall campaign. Access to the underlying AI models was provided through the service OpenRouter. On August 25, the account in use showed expenses of around $7,000 over four weeks; over the following three weeks, the daily number of requests roughly doubled — meaning total costs were likely between $12,000 and $18,000. The attacker's own cost breakdown shows an average of $25.46 per targeted victim.

The instructions given to the AI agents were written in Chinese. Most of the stolen credit cards originated from the US (79.0%), followed by the United Arab Emirates (2.2%), Saudi Arabia (1.1%), the United Kingdom (1.0%), and New Zealand (0.9%).

Assessment

This campaign marks a notable shift: cyberattacks on e-commerce systems can now be carried out at large scale with comparatively low financial investment and minimal human oversight. The stated cost of around $25 per target is disproportionately low compared to the potential damage caused by 600,000 stolen credit card records.

For online store operators and connected security infrastructures, this means that traditional, manually conducted waves of attacks are increasingly being supplemented or replaced by automated, AI-driven attack chains. The speed — often just a few hours from initial access to full compromise — significantly complicates reactive defense measures and puts existing attack detection processes to the test.

Practical Tips

  • The interim report published by Gambit Security contains Indicators of Compromise (IOCs) that administrators can use to check whether their systems were affected by the campaign.
  • Online store operators should regularly check their payment systems for unauthorized scripts in the checkout area, since skimmer scripts were specifically placed there.
  • Given the short time span between initial access and full compromise, timely detection of unusual system activity is crucial.
  • Companies in particularly affected industries such as hospitality, aviation, industrial distribution, and fashion retail should specifically compare the attack patterns documented in the report against their own infrastructure.

Outlook

Since the activities are reportedly still ongoing and the attacker has already set up new servers after Cloudflare shut down the previous infrastructure, an imminent end to the campaign is not to be expected. The researchers also assume that the actual scale of the attacks is larger than documented so far, as the analysis of the data from the staging server is not yet complete.

For the security industry, this case is likely to serve as an example of a new category of threats in which AI agents no longer merely provide support but largely independently carry out entire attack chains — from vulnerability discovery to data exfiltration. Providers of security solutions and operators of critical infrastructure will need to adapt their detection and defense mechanisms accordingly.