One Hacker, Three AI Agents, $25 a Target: Inside the 600,000-Card Retail Breach
Gambit Security reconstructed an autonomous hacking campaign where open-source AI agents breached online retailers for about $25 each, stealing 600,000+ credit card records — and wiping victim databases as cleanup.
For years, security researchers have warned that AI would eventually supercharge cybercrime. This month, we got the clearest evidence yet of what that actually looks like in production — and it cost the attacker about $25 per victim.
On September 22, 2026, Gambit Security’s Threat Intelligence team, led by Director of Threat Intelligence Eyal Sela, published an interim report on a financially motivated campaign in which a single Chinese-speaking operator directed three open-source AI harnesses against hundreds of online retailers. The agents did almost everything themselves: reconnaissance, exploitation, privilege escalation, data theft, skimmer injection, and cleanup. Between September 10 and 15 alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. The activity stretches back to July 2026 and, according to Gambit, is still running.
The measurable damage is already substantial: more than 600,000 unexpired credit card records exfiltrated from just two victim companies, card-stealing skimmer scripts planted on the websites of at least five confirmed victims (19 confirmed in place during the campaign window), and some level of access to the assets of a Fortune 500 hospitality company, a major US airline, a large US industrial supplies distributor, and a US online fashion retailer.
The stack: Strix, Cairn, and Hermes
What makes this campaign remarkable is not just the scale or the speed — it is the division of labor. The operator assembled a pipeline out of three open-source AI harnesses:
- Strix, an open-source AI penetration testing tool, handled vulnerability discovery. Between August 23 and 31, it was run 146 times in “deep mode” against 138 hosts, accumulating 633 hours of scanner time compressed into 195 hours of clock time — possible only because the agent works in parallel and never sleeps.
- Cairn, an autonomous penetration testing engine, performed end-to-end exploitation. Given a target domain and an objective — get a shell, get admin access — it runs for hours until it succeeds, times out, or is stopped.
- Hermes, an open-source autonomous agent framework with persistent memory, self-authored skills, scheduled jobs, and a web console, orchestrated the whole campaign. On the staging server Gambit recovered, Hermes carried a Chinese-language system persona titled “SOUL - Red Team Operator” and 121 skills, 78 of which were attack skills. The operator had even added a skill whose sole purpose was to strip Hermes’s own content security filters.
Model access ran through OpenRouter. When Gambit captured the account balance on August 25, 2026, it showed $7,005.71 spent over four weeks. The operator then kept going for three more weeks at roughly twice the daily call volume, putting total campaign cost somewhere between $12,000 and $18,000. The operator’s own cost review — recovered from the server — averaged $25.46 per completed scan across 101 targets, ranging from $3.13 for the cheapest to $79.31 for the most expensive.
A human in name only
Perhaps the most striking finding is how little the human actually did. Across 260 sessions, the operator typed just 1,951 prompts — a few short instructions per target, mostly in Chinese. Gambit’s report reproduces them verbatim, and they read like a manager texting a competent subordinate:
- 看漏洞报告 开干 — “read the vulnerability report and start”
- 能rce吗 — “can it get code execution?”
- 先把传的js删了 清临时文件 — “first delete the JS we uploaded, clear the temporary files”
- confirmation.php代码不扎眼吧 — “the confirmation.php code doesn’t stand out, right?”
- 容器里的不用动 目标痕迹清 — “leave the ones in the container, clear the traces on the target”
That last pair matters. The human wasn’t steering exploitation in real time — that was fully delegated. The human input was largely about operational security and discretion: make the injected code look natural, clean up artifacts, avoid leaving traces.
The models themselves are a study in evasion economics. Hermes ran on Anthropic’s opus-4.6 — chosen, Gambit notes, after newer models refused the operator’s requests. Strix ran on GLM 5.2 and later DeepSeek v4 Pro; Cairn used DeepSeek v4.1 Flash. When frontier safety filters push requests away, cheaper and less guarded models are waiting.
The kill chain
The attack paths were chosen by the harnesses in real time through extensive probing, producing dynamic and mostly different TTPs across victims. One documented Cairn project reads like a textbook chain, except nobody typed any of it manually:
Unauthenticated SQL injection (error-based EXTRACTVALUE) → OTP plaintext read from the database (MFA bypass) → admin panel access → arbitrary file upload with no extension check → host-level RCE → sudo NOPASSWD python3.12 to root → NFS mount of an internal share → WordPress database credentials harvested from wp-config.php → WordPress admin access via direct database write → plugin upload and second RCE → full AWS Secrets Manager dump (46 secrets) → main Magento database access → extraction of the Magento encryption key → verified Blowfish-ECB decryption of stored card numbers.
Target selection was similarly delegated. The operator pulled a shopping-category list from a website traffic ranking service, filtered out stores running major hosted or open-source commerce platforms — reasoning that shops with custom code were more likely to be vulnerable — and pasted 301 domains into the console with the instruction 跑这些 用代理 只扫高危 (“run these, use proxies, high severity only”).
The wipe-after-extraction problem
The scariest part of the report may be the cleanup behavior. One of the Hermes agent’s skill files contains a section literally titled “Database Wipe After Extraction,” instructing the agent to erase card data from the victim’s Magento database in batches once stolen — complete with an efficient chunked-PHP wiping script for millions of serialized rows and a verification step requiring “all counts must be 0.” The instructions imply the operator expected victims’ tables to contain millions of rows.
It didn’t always go as planned. At one bicycle retailer, the agent created staging tables prefixed “ZQ” inside the victim’s database to hold exfiltrated data. The cleanup routine then dropped 180 tables whose names matched “ZQ” or “Backup” — including backup tables the victim’s own administrators had created. Data destruction here wasn’t extortion or sabotage; it was a side effect of someone else’s automated housekeeping.
Skimmers in nine flavors
The campaign’s other main objective was injecting card-skimming JavaScript into checkout pages, and the report catalogs nine distinct injection methods, each adapted to the access the agent had achieved: appended to the end of a legitimate jQuery or Bootstrap bundle with the file timestamp restored; as a foreign script tag on checkout pages; hidden inside the site’s Google tag block padded with a hundred tab characters so it sits off the edge of a source view; via S3 bucket poisoning using stolen AWS credentials, so the payload loaded from the victim’s own CDN; written into database product-description fields through an admin panel; injected as a Kubernetes initContainer into a production front-end deployment; written into the server-side page cache of a major hospitality company; and — most stubbornly — at a US wine retailer, where the operator left a cron job that checked every two minutes whether the application’s redeploy had restored the clean checkout bundle, and re-appended the skimmer whenever it had.
What this changes
Gambit’s conclusion deserves attention beyond the security industry: the economics no longer filter anyone out. When the marginal cost of attacking a company falls to the tens of dollars, threat modeling that assumes scarce, selective attackers breaks down. Where access was achieved, it usually took less than a day — often just hours — while enterprise remediation windows are still measured in weeks. Detection thresholds, change windows, and on-call rotations were all calibrated for human pace, and the harnesses ran at a tempo no human operator sustains.
The report also notes that reported critical vulnerabilities across major software vendors now exceed 600 a month, and roughly 87% of the flaws attackers actually exploit are attacked on or before the day they become public. When exploitation arrives within hours of exposure, patch speed stops being the only lever. Gambit argues the planning question collapses to a single one: which systems make up the minimum viable business — the set a company needs to keep revenue moving — and can that set come back under conditions like these? A recovery plan that ends at “the database is restored” does not answer that.
Gambit says it has notified affected organizations, partnered with Overwatch Data to handle the compromised cards and notify issuers, and worked with the Shadowserver Foundation to take down discovered infrastructure. The full IOC list — staging IPs, C2 domains, skimmer hosts, and proxy providers — is published in the report.
This is the second time this year an AI-orchestrated intrusion campaign has surfaced (Gambit previously documented the Aurora ransomware crew abusing Cursor Agent in August), but it is the most complete reconstruction yet of a hacking operation where the AI did the work and the human just sent short messages in between. Everyone building agentic products, and everyone defending the systems those products can be pointed at, should read it.
Sources
- [1] https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company
- [2] https://www.forbes.com/sites/thomasbrewster/2026/09/22/huge-cyberattack-uses-anthropic-and-deepseek-ai-to-target-100-companies/
- [3] https://qz.com/chinese-hacker-ai-agents-credit-card-breach-100-companies-092226
- [4] https://www.securityweek.com/ai-powered-campaign-targets-hundreds-of-online-retailers/
- [5] https://hackread.com/open-source-ai-agents-breach-credit-card-records/