Malicious AI agents have been unleashed on hundreds of online retailers, stealing more than 600,000 credit card records and infecting over 100 websites with skimmers. The attacks are carried out by financially motivated threat actors using open-source AI agent frameworks to target vulnerable companies at scale.
The campaign has been ongoing since at least July, with the attackers compromising at least 27 companies in just five days. Two of the targeted companies had their credit card databases breached, resulting in over 600,000 stolen card details. Five other organizations had skimmers injected into their websites, allowing the attackers to collect payment data from unsuspecting customers.
The AI tools used by the attackers are complex and sophisticated, with three main components driving the attack chain: Strix, Cairn, and Hermes. Strix is a penetration testing framework that scans for vulnerabilities, while Cairn is an autonomous exploitation engine that aims to gain admin access or obtain a shell on compromised systems. Hermes is responsible for campaign orchestration, post-exploitation work, and tactical decisions.
The attackers are using these tools to launch tens of attacks every day, with the human operator providing brief instructions before letting the AI agents handle the rest. Between September 10 and 15, the attacker launched 105 distinct attack waves, succeeding to varying degrees on at least 27 targets.
One of the most concerning aspects of this campaign is the use of skimmers to collect payment data from websites. The attackers are using various methods to inject malicious code into legitimate JavaScript files, including appending script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, and altering Kubernetes deployments.
The low per-target costs of this operation are also alarming. Gambit researchers found an OpenRouter account showing $7,005.71 spent over roughly four weeks, with estimated total costs between $12,000 and $18,000. This adds up to an average cost of $25 for each target, making it easy for threat actors to deploy such attacks.
The use of AI agents in this campaign is a worrying trend that highlights the need for organizations to plan against potential data loss as a side effect of the attacker’s cleanup routine. The attackers are instructing their AI agents to remove card data from Magento databases after exfiltration, causing operational disruptions at several retailers due to data losses.
As a result, it is essential for online retailers to take proactive measures to prevent such attacks. This includes regularly updating software and plugins, conducting thorough penetration testing, and implementing robust security protocols to detect and respond to potential threats. By being aware of the risks and taking proactive steps, organizations can reduce their vulnerability to these types of attacks.
Source: Bleeping Computer — 2026-09-23