AI agents ran a card-skimming spree on online shops: 600,000 cards, about $25 a victim
Gambit Security recovered an attacker's staging server: three open-source AI agents broke into 27 companies in five days, stole 600,000+ card records and planted skimmers on 100+ sites.
On September 22, 2026, the threat intelligence team at Gambit Security published an account of a campaign in which a single operator pointed three off-the-shelf, open-source AI agents at online retailers and let them do the hacking. Gambit recovered the attacker's staging server and reconstructed the operation from it: at least 27 companies compromised in the five days between September 10 and 15, more than 600,000 unexpired credit card records taken from two of them, and payment-stealing code confirmed on well over 100 websites. If your organisation takes card payments on its own website — especially on Magento or WordPress — this is a same-week check, not a next-quarter project.
What happened, in plain English
A "skimmer" is the online equivalent of a card reader glued over a petrol pump keypad. The attacker adds a small piece of JavaScript — the programming language that runs inside your customers' browsers — to a shop's checkout page. The page looks and works exactly as before. The payment still goes through. But as the customer types, a copy of the card number, expiry date and security code is quietly sent to the attacker. Shop owners typically discover it weeks later, from their bank or their payment processor.
What is different here is who did the work. The operator did not write custom tooling. They rented three publicly available AI agent frameworks — Strix, Cairn and Hermes — and connected them to commercial AI models. An "agent framework" is software that lets an AI model act rather than just talk: run a command, read the output, decide what to do next, repeat. Strix scanned for weaknesses using the GLM 5.2 and DeepSeek v4 Pro models. Cairn ran automated intrusion attempts on DeepSeek v4.1 Flash. Hermes handled the hands-on-keyboard work using Anthropic's Claude Opus 4.6, loaded with 121 "skills", 78 of which Gambit classifies as attack skills.
The human's contribution was thin. Gambit counted 1,951 prompts across 260 sessions from one operator — short tactical instructions in Chinese, along the lines of "read the vulnerability report and start" or "get into the web backend." Between those nudges, the agents worked on their own.
The economics are the part worth remembering. Gambit puts the average model cost at $25.46 per targeted company, ranging from $3.13 to $79.31, and the whole four-week campaign at roughly $12,000 to $18,000. A snapshot of the operator's account balance on August 25, 2026 showed $7,005.71 spent.
Are you affected? What to do now
You should care if your organisation runs its own e-commerce checkout, or if you are responsible for a website that handles payment or personal data. Gambit's confirmed victim list is broad rather than sector-specific: a Fortune 500 hospitality company, a major US airline, an industrial supplies distributor, a Japanese travel booking site, a print-on-demand platform, retailers of fashion, wine, bicycles, beauty products and steel. Magento stores were a clear focus — the agents went directly for the sales_flat_order_payment and sales_flat_quote_payment database tables — but WordPress sites, custom platforms and Kubernetes and AWS environments were also hit.
Working checklist, roughly in order of value:
- Check your checkout pages for unexpected scripts. Compare the scripts loading on your live payment pages against what you expect to be there. The skimmer Gambit observed was a short, base64-encoded loader that injects an extra script tag into the page.
- Search your logs and blocklists for Gambit's published indicators. Domains:
medbooksource[.]com,static-js[.]com,cdn[.]netlfjs[.]com,x1opay[.]co. IP addresses:155.254.22.215,209.126.4.170,213.21.239.62,172.245.224.188,172.245.89.137. These come from Gambit's report; treat them as leads to investigate, not a complete list. - Assume the window is hours, not days. Eyal Sela, Gambit's director of threat intelligence, told The Register that "where access was achieved, it usually took less than a day, and in many cases just a few hours." Alerting that pages a human the next morning is too slow for this tempo.
- Close the unglamorous configuration gaps. The entry routes Gambit lists are familiar ones: injection flaws in login forms, unrestricted file uploads,
sudo NOPASSWDentries, NFS exports withno_root_squash, writable S3 buckets, cache poisoning, and Kubernetes deployments an attacker could modify. Nothing exotic — but the agents tried all of them, quickly, against every target. - Review who can change your checkout. Content delivery network configuration, third-party tag managers and marketing scripts are all routes onto a payment page. Ask your suppliers who can push JavaScript to your checkout, and how that is reviewed.
- Test that you could actually recover. Gambit documented the attacker instructing the agents to wipe card fields after exfiltration as a cleanup step; in one case a database wipe hit 180 tables, including customer backups. Data loss here arrived as a side effect of someone else's tidying up.
- If you find a skimmer, treat it as a payment incident. Notify your acquirer and payment service provider, preserve logs before rebuilding, and follow your PCI DSS incident obligations. Gambit says it has contacted many affected organisations, with help from the Shadowserver Foundation, so a notification may reach you independently.
If you do not run your own checkout and your payments are fully hosted by a provider, your direct exposure is limited — but the configuration hygiene points above still apply to whatever you do host.
The expert view
Nothing in the tradecraft is novel. Magecart-style skimming has been an industry for the better part of a decade, and every entry vector Gambit lists would have worked in 2018. What has changed is the cost curve of the labour between scan and payday.
The historic constraint on mass e-commerce compromise was human attention. Someone had to look at a scanner's output, decide which of forty findings was real, chain them, work out where the payment tables lived on an unfamiliar platform, and write a skimmer that survived the site's own deployment process. That is skilled work, and it does not parallelise well across a person. Sela's framing is the one to take away: "The harnesses ran at a tempo no human operator sustains, with the person reduced to short instructions between autonomous runs."
The chains themselves are worth understanding conceptually, because they show the agents reasoning rather than replaying a script. In one documented case the path ran from an injection flaw in a login field, to reading one-time passcodes straight out of the database — defeating multi-factor authentication not by breaking it but by stepping around it — to the admin panel, to a file upload with no type checking, to running code on the host. Each step was chosen based on what the previous step returned. A scanner cannot do that; a junior penetration tester can, and now so can a $25 agent run.
Two implications follow. First, the defender's assumption that low-severity findings stay low-severity because "nobody will bother chaining them" is now an economic bet that has lost. Second, "targeted" and "opportunistic" have stopped being useful opposites: Gambit describes 105 attack projects launched across five days, each receiving bespoke handling. Breadth at depth used to require a team.
What remains unknown matters too. Gambit attributes the campaign to no group and no state — it observes only that the operator's prompts and commands were written in Chinese, which is an observation about language, not about nationality or sponsorship. The total number of companies targeted is described as "hundreds" without a firm figure. No model provider or framework maintainer had commented publicly as of September 25, 2026, so there is no public account of whether the accounts involved were detected or suspended. And the skimmer count — 19 confirmed on named victims, plus more than 100 further sites identified with a linked skimmer by Gambit and the independent researcher Varys — is a floor, not a ceiling. The campaign was described as ongoing at publication.
Official sources
- Gambit Security — "Autonomous AI Agents Hack Online Retailers for $25 a Company" (September 22, 2026) — the primary research, including the indicators of compromise cited above
- Coverage: BleepingComputer (September 23, 2026) · The Register (September 25, 2026) · Hackread