
A financially motivated threat actor has been utilizing open-source artificial intelligence harnesses to launch largely unattended, automated attacks against hundreds of online retailers, resulting in the theft of more than 600,000 credit card records. Cybersecurity firm Gambit Security uncovered the campaign after recovering and reconstructing the attacker’s exposed staging server.
Between September 10 and 15, 2026, alone, the operator launched 105 attack projects and compromised at least 27 companies, though the activity dates back further to July 2026. The targeted entities include prominent names such as a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor, and a US online fashion retailer. Where access was achieved, the automated process typically took less than a day, and frequently just a few hours.
The AI Harness Architecture and Low Operating Costs
The operation relied on three distinct open-source AI frameworks working in tandem to handle the attack chain autonomously:
- Strix: An open-source AI penetration testing tool used for vulnerability discovery. Between August 23 and 31, 2026, it ran 146 times against 138 hosts, utilizing models such as GLM 5.2 and DeepSeek v4 Pro.
- Cairn: An autonomous penetration testing engine that took target domains and specific objectives (such as gaining shell or admin access) and executed probing and exploitation attempts dynamically. It used DeepSeek v4.1 Flash.
- Hermes: An autonomous AI agent featuring persistent memory, self-written skills, a searchable archive, and a web console. Loaded with a red-team operator persona and dozens of attack skills, Hermes orchestrated the campaign using Anthropic’s opus-4.6 model via OpenRouter.
The financial outlay for the campaign was exceptionally low. Across a four-week tracked period and subsequent high-volume weeks, total model API costs were estimated between $12,000 and $18,000. Across targeted entities, this translates to a marginal cost of just a few dollars to tens of dollars per company—averaging $25.46 over 101 completed scans.
Exfiltrated Data and Destructive Cleanup Routines
The threat actor successfully exfiltrated more than 600,000 unexpired credit card details from two primary victim companies. Working with anti-fraud specialist Overwatch Data, researchers mapped the geographical distribution of the compromised cards:
- United States: 488,372 cards (79.0%)
- United Arab Emirates: 13,559 cards (2.2%)
- Saudi Arabia: 6,785 cards (1.1%)
- United Kingdom: 6,522 cards (1.0%)
- New Zealand: 5,710 cards (0.9%)
- Ireland: 5,483 cards (0.9%)
- Singapore: 5,305 cards (0.9%)
- Kuwait: 4,676 cards (0.8%)
- Australia: 4,672 cards (0.7%)
- Hong Kong: 4,459 cols / cards (0.7%)
- France: 4,295 cards (0.7%)
- Qatar: 4,075 cards (0.7%)
- Remaining 196 countries: 64,025 cards (10.4%)
Beyond data theft, the campaign introduced severe operational disruptions. The Hermes agent included a “Database Wipe After Extraction” skill designed to erase stolen card data from source Magento database fields. In practice, automated cleanup routines frequently overreached; at one retailer, an agent dropped 180 tables matching specific prefixes, inadvertently wiping vital backup tables created by the victim’s own administrators.
Diverse Skimmer Injection Techniques
A core objective of the campaign was planting payment skimmers on checkout pages. Skimmers were ordered against at least 27 named victims and confirmed active on 19 during the campaign, with security researchers uncovering over 100 additional infected sites. Attackers deployed these skimmers using various innovative vectors depending on the technology stack:
- Appending loaders to the end of legitimate JavaScript library files like jQuery or Bootstrap and restoring original timestamps.
- Inserting foreign script tags directly into checkout pages.
- Embedding loaders within site Google tag blocks, padded with whitespace to sit off-screen.
- Exploiting AWS access keys to execute S3 bucket poisoning on victim CDNs.
- Modifying database content fields in product descriptions via administrative pods.
- Deploying injections within Kubernetes initContainers on production front-ends.
- Poisoning server-side page caches or establishing cron jobs to repeatedly restore scripts following application redeploys.
Industry Implications for Security and Resilience
This campaign demonstrates a fundamental shift in the threat landscape. Because the tooling is open source and operating costs are negligible, economic barriers no longer filter out advanced attackers. Furthermore, the relentless tempo of autonomous AI harnesses far exceeds human response capabilities, rendering traditional remediation windows obsolete in complex environments.
Gambit Security emphasizes that organizations must shift toward a resilience-first mentality. Because destructive data loss can occur as an unintended side effect of automated cleanup routines, businesses must clearly define and test their “minimum viable business” recovery frameworks to ensure critical operations can be rapidly restored under automated attack conditions.