threat_intelligence825 wordsRead on Arc Codex

AI-Powered Campaign Targets Hundreds of Online Retailers

A threat actor is using autonomous AI agents in an ongoing campaign targeting hundreds of online retailers, cybersecurity outfit Gambit reports. Active since July, the campaign relies on three AI harnesses to automate the attack chain, including vulnerability research, exploitation, and orchestration. “Between 10 and 15 September alone, 105 attack projects were launched, and at least 27 companies were compromised to varying degrees,” Gambit says. The hackers stole information from over 600,000 unexpired credit cards from two of the compromised companies and injected skimmer scripts into five online stores. Additionally, they gained some access to a Fortune 500 hospitality company and to three US firms, including an airline, a private industrial supplies distributor, and an online fashion retailer. “The campaign goes back further, and has impacted at least tens of other companies since July 2026. Where access was achieved, it usually took less than a day, and in many cases just a few hours,” Gambit notes. Open source AI tools for automation Mounted by a Chinese-speaking, financially motivated threat actor, the campaign used the open source AI penetration testing tool Strix for vulnerability hunting. Between August 23 and 31, the attackers ran it 146 times in ‘deep mode’ against 138 hosts, through OpenRouter on GLM 5.2 and on DeepSeek v4 Pro. The generated reports were then handed to the autonomous penetration testing engine Cairn, which was used to launch 105 attack projects between September 10 and 15 on DeepSeek v4.1 Flash. Gambit retrieved 48 of the attack reports, as the others were deleted. “Each attack path was chosen by the harness in real time through extensive probing and exploitation attempts, resulting in dynamic and mostly different TTPs across victims,” Gambit notes. For the third stage of the attack, the threat actor used the open source autonomous AI agent Hermes, which has persistent memory, self-written skills, a searchable session archive, and a web console, and supports scheduled jobs. The adversary loaded a Chinese system persona and 121 skills, including 78 attack skills. Using Anthropic’s opus-4.6, Hermes handled orchestration, intrusions, tactical guidance, and direct hacking activities. Gambit identified “1,951 prompts typed by the human across 260 sessions – only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.” 600,000 credit cards stolen at marginal cost The threat actor used a website traffic ranking service to select targets, focusing on shops running custom code. A human operator pasted 301 results into the console, but also handpicked at least two targets for which they already had an administrator password. According to Gambit, at least 600,000 credit card records were stolen from two victim companies, including over 488,000 cards from the US. The cybersecurity firm also identified a Hermes agent skill designed to delete the stolen card data from the victim’s Magento database. Additionally, the agent deleted a bicycle retailer’s backup tables after being instructed to erase staging tables created within the database. As part of the campaign, the threat actor also focused on injecting skimmer scripts into online shops’ checkout pages. Gambit initially confirmed 19 victims. Working with security researcher Varys, it discovered over 100 additional infected websites. The skimmer was typically appended to a JavaScript file present on the website, but the threat actors also deployed it as a script tag, inside the site’s Google tag block, in an AWS S3 bucket, in database content fields, in a Kubernetes initContainer, and in the cached page model of the checkout page. “At a US wine retailer, the application redeploy restored the clean checkout bundle, so the operator left a cron job in the JBoss log directory that checked the file size every two minutes and appended the skimmer again whenever it was reverted,” Gambit notes. What matters most about the campaign, the cybersecurity firm notes, is that the operator incurred marginal cost through the use of open source tooling. Based on the retrieved data, Gambit estimates a mean cost of $25.46 over 101 completed scans. “This is a very concerning incident which demonstrates what the future of cyberattacks will more commonly look like. When the major AI players announced their agents had carried out breaches in testing scenarios, this caused serious concern, but given that these activities were not deliberately malicious, the incidents were contained,” Talion Cyber Security threat intelligence analyst Daniel Wilcock said. “Here we are seeing something very different. AI was deliberately used to maliciously target organizations under the pretense of running a pen test. This wasn’t social engineering; it was a full-scale attack, where agents were prompted to probe for weaknesses, which they did persistently, and wipe clean any evidence of the assault,” Wilcock added. Related: Astrana Health Data Breach Impacts Private, Confidential Information Related: Hackers Return $263 Million Stolen From Liquid Network Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted Related: Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.