Gambit researchers uncovered ongoing AI‑driven skimming campaign stealing 600,000+ payment records since July 2026 Attackers used three autonomous harnesses (Strix, Cairn, Hermes) to compromise dozens of retail sites cheaply Victims include major US firms; campaign shows AI enables faster, persisten
<![CDATA[ <article> <ul><li><strong>Gambit researchers uncovered ongoing AI‑driven skimming campaign stealing 600,000+ payment records since July 2026</strong></li><li><strong>Attackers used three autonomous harnesses (Strix, Cairn, Hermes) to compromise dozens of retail sites cheaply</strong></li><li><strong>Victims include major US firms; campaign shows AI enables faster, persistent, low‑cost cyberattacks at scale</strong></li></ul><p>In July 2026, a hacker tasked autonomous AI agents to attack retail organizations around the world, deploy <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">credit card skimmers</a>, and steal payment data. </p><p>Since then, the bots launched hundreds of attack projects, compromised dozens of organizations, and stole at least 600,000 <a href="https://www.techradar.com/best/best-payment-gateways" target="_blank">payment</a> records - and to make matters worse, the campaign is still live, attacking and breaking into websites as we speak. </p><p>All of this was <a href="https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company" target="_blank">reported</a> by security researchers Gambit, who said they managed to recover the operator’s staging server and through it - reconstruct the ongoing campaign. They also saw the skimmers live on victim websites, and sifted through logs and AI claims found on the attacker’s server. In just five days, between September 10 and 15, the agents made 105 attack waves and compromised 27 organizations “to varying degrees.”</p><p>Among the victims are a Fortune 500 hospitality company, a “major” US airline, a large private US industrial supplies distributor, and a US online fashion retailer. One of the AI tools would use a website ranking service to produce a list of potential targets, focusing primarily on those running custom-built software.</p><h2 id="a-fistful-of-dollars">A fistful of dollars</h2><p>But the victims are not the “interesting” part of this story - the attackers are. Gambit believes they are financially motivated Chinese threat actors. They are using three AI “harnesses” (frameworks, essentially), which can run almost the entire attack chain autonomously, striking around 10 companies a day, for a handful of dollars per company. </p><p>In four weeks, the attackers spent around $7,000, meaning that their entire cost for the operation so far was no more than $18,000. Breaking it down, it means that the attacker spent around $25 per target. </p><p>“Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company,” Gambit’s researchers said. “The operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.”</p><p>“Where access was achieved, it usually took less than a day, and in many cases just a few hours. We also detected instructions in the attacker’s playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent - and this has indeed happened in some of the breaches,” Gambit said.</p><h2 id="the-three-harnesses">The three harnesses</h2><p>The three harnesses are called Strix, Cairn, and Hermes. </p><p>Gambit describes Hermes as an open source autonomous AI agent with a persistent memory, skills that the agent wrote and edited itself, a searchable archive of past sessions, scheduled jobs, and a web console. On the staging server the researchers analyzed, it loaded a Chinese system persona called “SOUL - Red Team Operator”, which contained 121 skills (78 attack skills). </p><p>“Hermes is the operator’s console for orchestrating the activity and for direct hacking activities,” Gambit explained. “It used Anthropic’s opus-4.6 (after newer models refused its requests), with 1,951 prompts typed by the human across 260 sessions - only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.”</p><p>Strix is an open-source AI pentest tool, while Cairn is an autonomous pentest engine. It receives target domains and an objective, such as to get a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. Cairn used DeepSeek v4.1 Flash, it was said. </p><p>Gambit’s researchers seem to be rather impressed with the campaign. They described it as very low cost, with a level of patience, persistence, and creativity that most human attackers would be “unlikely to sustain”, managing to achieve “far greater results, far faster.” </p><p>They have also called to arms, urging organizations to “adapt to a reality where attacks are significantly faster and more comprehensive.” To do that, they must adopt a resilience-first mentality and deploy a security stack that can match the AI on speed.</p><p>Many of the affected organizations were notified, and the skimmers were removed, they said.</p> </article> ]]>

Read the full article on TechRadar
Read Full Article →