Home Technology Artificial Intelligence A Hacker Put AI Agents to Work—and 600,000 Credit Cards Were Stolen

A Hacker Put AI Agents to Work—and 600,000 Credit Cards Were Stolen

Representational image of a hacker

This post is also available in: עברית (Hebrew)

Cyberattacks against online retailers traditionally require significant manual work: finding vulnerable websites, breaking into each system, installing malicious code and returning later to collect stolen data. AI agents are beginning to compress that process, allowing one operator to attack many organizations simultaneously with relatively little direct involvement.

An ongoing campaign uncovered by Gambit Security shows how far that automation can go. According to the researchers, a Chinese-speaking attacker used several AI agents to target hundreds of online retailers, compromising more than 100 websites with payment-card skimmers and stealing over 600,000 valid credit card records.

Between September 10th and 15th, 2026, alone, the system launched 105 attacks and compromised 27 organizations to varying degrees. According to Cyber News, once initial access was achieved, automated agents could sometimes complete the intrusion, data theft and cleanup within hours.

The operation uses three AI frameworks for different stages.

Strix, an open-source AI penetration-testing tool, searches targets for vulnerabilities. Cairn handles more autonomous exploitation: it can receive a domain and an objective, such as obtaining administrative access, then continue working until it reaches that goal. A third agent, Hermes, coordinates the wider campaign, launches intrusion jobs and provides guidance about subsequent actions.

Together, the tools effectively create an automated cyberattack pipeline. The human operator still defines objectives and provides instructions, but does not need to manually perform every technical step. Across 260 observed sessions, researchers recorded only 1,951 short human prompts.

One major objective was injecting malicious web skimmers into checkout pages. These scripts secretly capture payment-card information entered by customers and send it to the attacker. Researchers identified more than 100 websites infected with skimmers linked to the campaign.

The automation was also relatively inexpensive. The company estimates the attacker spent between $12,000 and $18,000 on AI-model tokens since July. The operator’s own calculations reportedly placed the average AI cost at $25.46 per completed scan, ranging from $3.13 to $79.31.

The campaign also demonstrates a less obvious risk of autonomous attacks. After stealing payment information, the agents were instructed to erase credit-card data from compromised Magento databases. In one case, an automated cleanup routine reportedly destroyed victim data.

For cybersecurity teams, the important change is speed. Defensive processes that take days or weeks increasingly face automated attackers capable of moving from discovery to data theft within hours.

The technology does not remove the human attacker from the operation. Instead, it allows one person to delegate much of the repetitive technical work to software and pursue dozens of targets in parallel.

That changes the economics of cybercrime: an attacker no longer needs a large team to dramatically increase the number of organizations they can attack at once.