AI agents are no longer just being tested for cybersecurity research. A financially motivated threat actor has reportedly used autonomous AI tools to attack online retailers, compromise dozens of organizations and steal more than 600,000 payment card records.
CyberInsider reported that the campaign has been active since at least July, with researchers from Gambit Security reconstructing the operation after gaining access to the attacker’s staging server. Between Sept. 10 and Sept. 15 alone, Gambit identified 105 attack projects involving at least 27 organizations.
The operation relied on three open-source AI tools: Strix for finding vulnerabilities, Cairn for autonomous exploitation and Hermes for coordinating attacks after access was obtained. The attacker reportedly issued short instructions while the AI agents handled much of the reconnaissance, exploitation and post-compromise activity.
The stolen payment data came from two compromised companies and included more than 600,000 unexpired card records, according to Gambit. Researchers also identified skimming activity across online stores, with malicious code inserted through several methods, including website scripts, databases and cloud-hosted content. More than 100 additional websites were later linked to the campaign’s infrastructure.
Perhaps the most concerning part is the economics. Gambit estimated that the attacker spent between $12,000 and $18,000 on AI model access during the campaign. Its analysis of recovered data put the average cost at about $25 per completed target, with some scans costing only a few dollars.
The campaign also shows how autonomous systems can create risks beyond data theft. Researchers found evidence that AI-driven cleanup routines could delete data or disrupt compromised systems, including an incident in which database tables were reportedly removed from a victim.
The findings point to a changing cybersecurity landscape where attackers can automate large portions of the traditional hacking process. Instead of relying on a human to manually investigate and exploit every target, AI agents can continuously probe systems, adapt their attack paths and move to the next victim at relatively low cost.
For online retailers, that could make defending against automated attacks increasingly difficult as the same AI technology powering enterprise automation becomes available to cybercriminals.








Reader Discussion
Join 0 thoughts shared by the communityBe the First to Comment
No discussions started yet. Share your feedback or insights with the TechCrest community!