The news
Gambit Security on September 22 described an ongoing AI agent hacking campaign in which one financially motivated operator used three open-source AI tools to attack hundreds of online retailers. Gambit said at least 27 companies were compromised between September 10 and September 15 alone, that at least tens of others had been hit since July, and that over 600,000 card records were stolen.
The security firm said it reconstructed the operation after recovering the attacker's exposed staging server, including stolen data, tooling and logs. According to Gambit's director of threat intelligence, Eyal Sela, the operator communicated in Chinese, and the activity began in July 2026 and was still running when Gambit published. The operator launched 105 attack projects in the September 10 to 15 window. The Register reported that the attacker's account showed about $7,005 in spending over the four weeks before August 25.
Gambit said the operator combined three tools, all accessed through the OpenRouter model marketplace. Hermes, an autonomous agent loaded with a persona called Red Team Operator and 121 skills, 78 of them attack-focused, ran on Anthropic's Opus 4.6 model. Strix, a penetration testing tool running on GLM 5.2 and later DeepSeek v4 Pro, ran 146 deep scans across 138 hosts. Cairn, an exploitation engine on DeepSeek v4.1 Flash, chose attack paths on its own.
Victims named by category included a Fortune 500 hospitality company, a major U.S. airline, a large industrial supplies distributor and retailers selling fashion, bicycles, beauty products and wine, Gambit said. It verified card skimmers, code that copies payment details as shoppers type, on at least 19 sites and detected more than 100 additional infected websites. The 600,000-plus unexpired card records came from two companies, and 79% were U.S.-issued. Gambit did not name the victims, none has publicly confirmed a breach, and its findings have not been independently verified.
Gambit said the attacks used techniques including SQL injection, multifactor authentication bypass, malicious file uploads and privilege escalation. In one case, the agent's cleanup routine wiped 180 database tables, including admin backups, at a bicycle retailer. The Register quoted Sela as saying that where access was achieved, it “usually took less than a day, and in many cases just a few hours.” Gambit said it contacted affected organizations and worked with the Shadowserver Foundation on takedowns.
The numbers
- Companies compromised Sept 10-15 alone
- At least 27
- Card records stolen (from two companies)
- More than 600,000
- Sites with verified skimmers
- 19+ (100+ more detected)
- Average cost per target
- About $25 ($3.13 to $79.31)
- Estimated total campaign cost
- $12,000 to $18,000
- Attack projects launched Sept 10-15
- 105
Why CEOs should care
For CISOs at retailers, travel and hospitality firms, the practical message is that opportunistic attackers now probe at a scale and persistence once reserved for targeted campaigns. Checkout and payment pages deserve continuous monitoring for unauthorized script changes, because skimmers sit quietly in the browser while orders process normally. Security teams should also confirm that long-known weaknesses, such as SQL injection and unsafe file uploads, are closed on every storefront, including regional sites and acquired brands.
For CFOs, the economics have shifted. Gambit estimates each target cost the attacker about $25 in AI usage. The payoff can be large: in this campaign, card records taken from just two companies topped 600,000. Finance leaders should check whether cyber insurance and payment processor agreements cover skimming incidents and how quickly the company could detect one.
For boards, the destroyed database tables are the overlooked risk. The agent wiped data after extraction, and one retailer lost admin backups in the process. Ask whether backups are isolated from production credentials, and whether the company has defined the minimum systems it needs to keep selling during recovery, as Gambit recommends.
The bigger picture
Gambit's findings show one attacker using commercial and open-source AI models to automate intrusions, from scanning to data theft. The tools involved here are publicly available, and the models were rented through a mainstream API marketplace, which lowers the skill and money needed to run a broad attack.
Gambit argues that defenders' remediation windows are still measured in weeks, while AI-driven attackers move in hours. That gap favors a resilience-first approach: assume some breaches will succeed and invest in fast detection and recovery.
What’s next
Watch for victim disclosures, card network alerts and any response from AI model providers and OpenRouter on detecting attack tooling that runs through their services. Retailers should review payment-page integrity controls and database backup isolation now, rather than after a skimming alert from their card processor.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







