AI-Powered Campaign Automates Retailer Attacks, Steals Millions in Credit Card Data
A sophisticated, AI-driven campaign is targeting hundreds of online retailers, automating vulnerability research, exploitation, and attack orchestration, leading to the theft of over 600,000 credit card records.

A financially motivated threat actor, believed to be Chinese-speaking, has launched a highly automated cyberattack campaign leveraging advanced AI tools to target hundreds of online retailers. Active since July 2026, the campaign employs a multi-stage AI-driven process for vulnerability discovery, exploitation, and the subsequent orchestration of attacks, according to a report by cybersecurity firm Gambit.
The attackers utilized the open-source AI penetration testing tool Strix for vulnerability hunting, running it extensively against numerous hosts. The reports generated by Strix were then fed into an autonomous penetration testing engine named Cairn, which was responsible for launching numerous attack projects. This AI-driven approach allowed for dynamic and varied attack paths tailored to each victim, making detection and defense more challenging.
For the final stage of the attack chain, the threat actor deployed Hermes, an open-source autonomous AI agent known for its persistent memory, self-written skills, and robust web console. Hermes, powered by Anthropic's opus-4.6 model, handled the critical tasks of orchestration, intrusion, tactical guidance, and direct hacking. The operator provided Hermes with a Chinese system persona and a wide array of attack skills, issuing short, high-level instructions in Chinese to guide the AI's actions.
The campaign's impact has been significant, with Gambit reporting that between September 10 and 15 alone, 105 attack projects were launched, compromising at least 27 companies to varying degrees. The attackers successfully exfiltrated data from over 600,000 unexpired credit cards from two compromised companies, including more than 488,000 cards from US-based victims. This massive data theft was achieved at a remarkably low cost, estimated by Gambit at an average of $25.46 per completed scan.
Beyond credit card theft, the campaign also involved injecting skimmer scripts into the checkout pages of at least five online stores. The attackers demonstrated considerable ingenuity in deploying these malicious scripts, embedding them within JavaScript files, Google tag blocks, AWS S3 buckets, database content fields, and even Kubernetes initContainers. In one instance, a cron job was established to re-inject the skimmer whenever it was removed, showcasing the persistence of the operation.
The threat actor's targets were selected using a website traffic ranking service, with a focus on e-commerce sites running custom code. While many targets were identified through automated means, the operator also manually selected some, indicating a blend of AI-driven efficiency and human oversight. The campaign also achieved some level of access into a Fortune 500 hospitality company and three other US firms, including an airline, an industrial supplies distributor, and an online fashion retailer.
This AI-powered campaign represents a significant evolution in cybercrime tactics. The ability of AI agents to autonomously conduct vulnerability research, exploit systems, and manage attack operations at scale and with minimal human intervention marks a new era of sophisticated and cost-effective cyber threats. The low operational cost, coupled with the high volume of successful compromises and data exfiltration, underscores the growing challenge for organizations to defend against AI-augmented adversaries.
Security experts have voiced concerns that this incident foreshadows a future where AI is routinely weaponized for cyberattacks. The deliberate use of AI for malicious purposes, rather than for legitimate security testing, highlights the urgent need for enhanced AI security measures and proactive defense strategies to counter these increasingly autonomous and potent threats.