THREAT BRIEFING · 29.09.2026 DEENFRES

News

AI Agents Steal 600,000 Credit Card Records

By Benedikt Langer · September 25, 2026 · 5 min read

An attacker used three open-source AI agents to attack hundreds of online shops and copied at least 600,000 unexpired credit-card records. The attack chain, from vulnerability discovery to the skimmer, ran largely automatically; according to the attacker’s cost breakdown, each target cost an average of around 22 euros.

Key takeaways

  • AI agents attacked hundreds of online shops largely automatically. A human issued short instructions in Chinese; the agents handled vulnerability discovery, exploitation and control.
  • The agents stole data from at least 600,000 credit cards that had not yet expired. Over 488,000 are from the USA, and Gambit confirmed skimmer scripts on 19 victims.
  • Each target cost an average of around 22 euros. That is according to the attacker’s cost breakdown; Gambit estimates the total cost at 10,600 to 15,800 euros.

Discovery Through Unprotected Servers

On 22 September, the security company Gambit Security documented an ongoing campaign against hundreds of online shops in a report. The company noticed the attacker because the attacker had inadvertently left the server infrastructure unprotected on the open internet.

The activity can be traced back to July 2026 and, according to Gambit, is still ongoing. Anthropic identified and suspended an account used for the attacks. Gambit is additionally working with Cloudflare and the Shadowserver Foundation to take down the attacker’s infrastructure. Cloudflare has shut down servers that the attacker repeatedly rebuilt.

What is a web skimmer? A web skimmer is a script that attackers inject into the checkout page of an online shop. It records the card details entered there and sends them to the attackers’ servers. Because it sits in the shop page’s own code, it remains invisible to customers.

105 Projects in Five Days

In mid-September, the attacker launched 105 attack projects and penetrated at least 27 companies to varying depths. Victims whose systems the attacker broke into include a Fortune 500 company in the hospitality sector, a major US airline, a large US distributor of industrial supplies and a US online fashion retailer. Where the attacker gained access, it usually took less than a day according to Gambit, and in many cases only a few hours.

At Least 600,000 Card Records

The agents copied at least 600,000 unexpired credit-card records from two of the compromised companies. Among them are over 488,000 cards from the USA.

The attacker ordered skimmer scripts to be installed on at least 27 victims; Gambit confirmed the scripts on the websites of 19. Together with the security researcher Varys, the company found over 100 more infected websites.

Three Open-Source Agents Direct the Attack

For the campaign, the attacker used the open-source AI agents Strix, Cairn and Hermes. Strix handled vulnerability discovery, Cairn executed automated attacks and exploits, and Hermes managed and directed the campaign. The model-routing platform OpenRouter provided access to the language models.

Between 23 and 31 August, Strix ran 146 times in Deep Mode against 138 hosts. The agent used GLM 5.2 and DeepSeek v4 Pro as its language models.

Hermes directed the campaign with Anthropic’s model Opus 4.6 after newer Anthropic models had refused its requests. The agent ran with a Chinese system persona and 121 skills, 78 of them for attacks.

Gambit identified 1,951 human-typed prompts across 260 sessions. The short instructions were written in Chinese.

22 Euros per Target

The OpenRouter account used for the attacks showed spending of around 6,200 euros for four weeks as of 25 August. Gambit estimates the total cost of the campaign at 10,600 to 15,800 euros.

In the attacker’s own cost breakdown covering 101 completed scans, the average came to around 22 euros per target, with a range of 3 to 70 euros. Gambit’s own calculation is in a similar range.

Eyal Sela, Director of Threat Intelligence at Gambit Security, explains: “The human is steering AI models that are almost fully autonomous and are now powerful enough to carry out highly sophisticated cyberattacks quickly, with almost no preparation and a very high success rate.” Daniel Wilcock, a threat intelligence analyst at Talion Cyber Security, describes the incident as “very concerning” and an example of what cyberattacks will look like more often in the future.

Gambit concludes from the campaign that companies must prepare for significantly faster and more comprehensive attacks. The company recommends that organisations prioritise resilience in their own security strategy. In Gambit’s view, companies should determine which systems support minimal business operations and how quickly those can be restored after an attack.

Frequently Asked Questions

Each question is locked. Tap to unlock the answer.

How much did each target cost?

According to the attacker’s cost breakdown covering 101 completed scans, each target cost an average of around 22 euros, with a range from around 3 to around 70 euros. Gambit estimates the cost of the entire campaign at 10,600 to 15,800 euros.

How was the campaign discovered?

The attacker had inadvertently left the servers unprotected on the open internet, which brought the operation to Gambit Security’s attention. Anthropic suspended the account used, and Cloudflare shut down servers the attacker repeatedly rebuilt.

Which AI agents were used?

The attacker used Strix for vulnerability discovery, Cairn for automated attacks and exploits, and Hermes for management and control. Models running through OpenRouter included GLM 5.2, DeepSeek v4 Pro and Anthropic’s Opus 4.6.

More from the MBF Media Network

cloudmagazinCloudflare: The Line Between Bot and Human Is Obsolete

Image source: AI-generated (September 2026)

A magazine by Evernine Media GmbH