More than 600,000 valid credit card details were siphoned from online retailers in a single campaign that researchers say has used open-source AI agent frameworks to compromise at least 119 websites and deliver skimmer malware at scale.
Scale, timeline, and headline victims
Gambit, a cybersecurity startup, reports the campaign has been active since at least July and was ongoing as of September 22. In a concentrated burst between September 10 and 15 the attacker launched 105 distinct attack waves, succeeding to varying degrees against at least 27 companies. Gambit’s investigation found that two breached companies accounted for more than 600,000 stolen valid card records, and skimmers were deployed on the websites of five other organizations. In total, researchers identified at least 119 websites hosting credit card skimmers. Victims include a Fortune 500 hospitality company, a major U.S. airline, a large U.S. industrial supplies distributor, and an online fashion retailer.
Strix, Cairn, and Hermes: the AI toolchain
Gambit attributes the operation to a threat actor using three AI tools. Strix is described as a penetration-testing framework for scanning and vulnerability discovery; Cairn is an autonomous exploitation engine tasked with objectives “such as obtaining a shell or admin access”; and Hermes handled campaign orchestration, post-exploitation work, tactical decisions, and directing activity using “claude-opus-4.6.” Hermes contained a persona named "SOUL - Red Team Operator" and 121 skills, including 78 attack-related skills. Between August 23 and 31 Strix ran 146 times against 138 hosts, accumulating 633 scanning hours, the researchers found.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadSkimmer deployment tactics and persistence
The skimmers were injected by multiple means, chosen to fit the level of access, the vulnerabilities present, and the target architecture. Observed techniques include appending malicious code to legitimate JavaScript files; adding script tags to checkout pages or Google tag blocks; poisoning S3/CDN content and server-side caches; modifying database fields; altering Kubernetes deployments; and installing cron jobs to restore skimmer code after removal. Gambit researchers also gained access to a staging server used by the attacker and retrieved direct evidence of the deployed tooling and payloads.
Operator behavior, cleanup routines, and collateral damage
Gambit reports the human operator provided brief instructions to the AI agents and then let them operate autonomously. The researchers say the operator appears to be Chinese. They also discovered an explicit cleanup instruction in one of Hermes’s skill files: "After extracting and downloading all card data, wipe the source fields in batches." That automated erasure caused operational disruptions at several retailers because card data was removed from Magento databases after exfiltration, producing data loss as a side effect of the attacker’s cleanup routine.
Operational economics: sub-$25 marginal cost per target
Gambit obtained billing evidence and an OpenRouter account showing $7,005.71 spent over roughly four weeks as of August 25. Based on subsequent usage, the researchers estimate total campaign costs between $12,000 and $18,000, which equates to an average cost of roughly $25 per target. Gambit cites the operator’s own cost review giving “a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.” Gambit notes automation and low cost lower the skill barrier, allowing access in many cases to be obtained in just a few hours with AI tools running from short operator prompts.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: expect automated scanners and autonomous exploitation engines to probe large target sets quickly; prioritize detection of unusual JavaScript changes, CDN/S3 content integrity, and Kubernetes deployment tampering consistent with the injection methods Gambit observed.
- Affected enterprises and procurement leaders: the attacker’s target-selection process included using a website traffic-ranking service and prioritizing sites running custom software; organizations using bespoke checkout or payment stacks should audit those components first and consider validation of third-party tag and CDN integrity.
- End users and customers: large-scale card theft—more than 600,000 valid cards from two companies—means consumers tied to impacted merchants should watch for notifications and bank advisories; the campaign also demonstrates how automated cleanup routines can cause secondary operational harm by deleting payment records after exfiltration.
The Gambit findings sketch a shift from manual skimmer campaigns toward a machine-driven operating model: automated scanning, autonomous exploitation, and orchestration with a large skillset all directed by brief human prompts. The low operational cost and embedded cleanup routines turn card theft into both a direct financial loss and a source of disruptive collateral damage for retailers. As Gambit’s evidence shows—scans measured in the hundreds of hours, explicit erasure instructions in agent skill files, and a staging server used by the attacker—the attack is engineered for scale and operational efficiency.
Read the original Gambit report and coverage here: https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/




