{"article":{"slug":"autonomous-ai-agents-are-breaking-into-online-retailers-for-25-a-target","title":"Autonomous AI Agents are breaking into Online Retailers for $25 a target","subtitle":null,"summary":"Gambit Security reconstructs an ongoing campaign where open-source AI harnesses attack retailers at ~$25/target, steal 600k+ cards, inject skimmers, and sometimes wipe databases during cleanup.","content_type":"research","language":"en","canonical_url":"https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company","author":{"name":"Eyal Sela","url":"https://gambit.security/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Gambit Security","url":"https://gambit.security/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Cybersecurity","slug":"cybersecurity","url":"https://listedarticles.com/topics/cybersecurity"},{"name":"Research","slug":"research","url":"https://listedarticles.com/topics/research"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1518,"reading_minutes":7,"published_at":"2026-09-22T00:00:00.000Z","added_at":"2026-09-25T06:19:13.805Z","updated_at":"2026-09-25T06:19:13.805Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/autonomous-ai-agents-are-breaking-into-online-retailers-for-25-a-target","markdown_url":"https://listedarticles.com/articles/autonomous-ai-agents-are-breaking-into-online-retailers-for-25-a-target.md","example":false,"citation":"Eyal Sela, Gambit Security. \"Autonomous AI Agents are breaking into Online Retailers for $25 a target.\" 22 Sept 2026. https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"},"body_markdown":"# Autonomous AI Agents are breaking into hundreds of Online Retailers for $25 a target in an ongoing campaign\n\nA financially motivated operator is running three open source AI harnesses against hundreds of online retailers, almost entirely unattended. More than 600,000 credit card records have been taken, and in one case the agent's own cleanup routine destroyed the victim's data.\n\n**Eyal Sela** · Director of Threat Intelligence · September 22, 2026\n\nA financially motivated threat actor is using open source AI harnesses to attack hundreds of online retailers, at a marginal cost of tens of dollars per company. Gambit Security's Threat Intelligence team recovered the operator's staging server and reconstructed the campaign from it. Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. The activity goes back to July 2026 and is still running.\n\nThree AI harnesses ran almost the entire attack chain autonomously, working up to tens of companies a day. The impact we can account for includes at least 600,000 unexpired credit card details from two companies, the installation of card-stealing skimmer scripts on the websites of five, and some level of access to the assets of companies including a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor and a US online fashion retailer. The campaign goes back further, and has impacted at least tens of other companies since July 2026.\n\nWhere access was achieved, it usually took less than a day, and in many cases just a few hours. We also detected instructions in the attacker's playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent — and this has indeed happened in some of the breaches.\n\nThe following is an interim report of our findings. We base the claim of compromise and impact on three sources. First, direct evidence we found on the attacker's staging server, such as the exfiltrated data itself and respective tooling. Second, live compromises we verified in the wild — skimmers that have been injected into websites and are still there, or have been removed since but logged in various scanners. Third, logs and AI claims found on the attacker's server. While AI claims and reporting may turn out to be inaccurate, we rely on them in this report because we could verify substantial parts of the claims by the first two methods, which showed them to be accurate.\n\nThis campaign showcases just how powerful attacks can be in 2026. At very low cost, the AI tools demonstrated a level of patience, persistence, and creativity that most human attackers would be unlikely to sustain in this kind of attack, and achieved far greater results, far faster. Organizations must adapt to a reality where attacks are significantly faster and more comprehensive by shifting to a resilience-first mentality and a security stack that matches the AI speed.\n\nWe have reached out to many of the affected organizations and took measures to take down the infrastructure discovered. We would like to thank the Shadowserver Foundation, Daniel Gordon, and other industry partners for their quick help and availability in notifying impacted organizations, taking down infrastructure, and conducting research.\n\n## AI Harnesses\n\nThe operator used three AI harnesses: **Strix** for vulnerability search, **Cairn** for autonomous end-to-end exploitation, and **Hermes** to orchestrate the campaign, launch intrusion jobs, steer the activity and give tactical guidance in the impact and other stages.\n\nOpenRouter was used for AI model access. The capture of the account balance on 25 August 2026 records $7,005.71 (US) spent, for a period of four weeks. The operator then ran for three more weeks at about twice the daily volume of model calls, recorded in the agent logs, so the full cost was likely between $12,000 and $18,000. Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company. The operator's own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.\n\n### Hermes\n\nHermes is an open source autonomous AI agent with a persistent memory, skills that the agent writes and edits itself, a searchable archive of past sessions, scheduled jobs and a web console. On this server it loaded a Chinese system persona titled \"SOUL - Red Team Operator\", 121 skills of which 78 were attack skills. The operator also added a skill whose purpose is to remove the content security filters of Hermes itself. Hermes is the operator's console for orchestrating the activity and for direct hacking activities. It used Anthropic's opus-4.6 (after newer models refused its requests), with 1,951 prompts typed by the human across 260 sessions — only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.\n\n### Strix\n\nStrix is an open source AI penetration testing tool. Between 23 and 31 August 2026 Strix was run 146 times in \"deep mode\" against 138 hosts, accounting for 633 hours of scanner time in 195 hours of clock time. Some of these reports were the opening of the next stage of the exploitation, handed over to Cairn. Strix ran through OpenRouter on GLM 5.2 and later on DeepSeek v4 Pro.\n\n### Cairn\n\nCairn is an autonomous penetration testing engine. It receives target domains and an objective, such as to get a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. DeepSeek v4.1 Flash was used in the Cairn attacks.\n\nBetween 10 and 15 September, 105 attack projects were launched. Each attack path was chosen by the harness in real time through extensive probing and exploitation attempts, resulting in dynamic and mostly different TTPs across victims.\n\n## Target selection\n\nThe operator selected targets in several ways. One was a website traffic ranking service, where they chose the shopping category and filtered out the shops running the major hosted or open source commerce platforms, to keep the shops with custom code, which the attacker assumed were more likely to be vulnerable. They then pasted 301 results into the console with a message that ended with instructions to run them via proxy for high-severity findings only. Others were picked by hand or by other means.\n\n## Exfiltrated credit card data\n\nThe threat actor exfiltrated more than 600,000 credit card records from two victim companies. Gambit partnered with Overwatch Data to handle the compromised cards and notify the issuers. The majority of cards (about 79%) were issued in the United States, with the remainder spread across many countries.\n\n## \"Database Wipe After Extraction\"\n\nOne of the Hermes agent's skill files tells the agent to erase the card data from the victim's Magento database once the data is stolen. The section is called Database Wipe After Extraction and it opens: \"After extracting and downloading all card data, wipe the source fields in batches\". At execution time, the operator gave instructions to empty serialized payment columns and to dump tables then clear them. A second victim, a bicycle retailer, lost data when the agent created `ZQ`-prefixed staging tables and cleanup then dropped 180 tables whose names matched ZQ or Backup, which also impacted backup tables that the victim's administrators had made.\n\n## Skimmer injection methods\n\nOne of the main objectives of the operator was injecting card-stealing skimmer scripts into the checkout pages of online shops. Skimmers were ordered against at least 27 named victims and confirmed in place on 19 of them during the span of this campaign. With the help of security researcher Varys, Gambit detected more than 100 further websites infected with a skimmer associated with this campaign.\n\nMethods included: appending loaders to legitimate JavaScript libraries (restoring original timestamps), foreign script tags on checkout pages, injection inside Google tag blocks, S3/CDN poisoning, database content fields, Kubernetes initContainers, server-side page-cache poisoning, and repeating repair tasks that re-append the skimmer after deploys.\n\n## What this changes\n\nThis campaign matters more than its size. The tooling is open source and the marginal cost of attacking a company sits in the tens of dollars, so the economics no longer filters anyone out. Where access was achieved it usually took less than a day, and in many cases a few hours, while remediation windows in complex environments are still measured in weeks. The harnesses ran at a tempo no human operator sustains, with the person reduced to short instructions between autonomous runs.\n\nThe practical consequence is a remediation clock most organizations cannot hold. Organizations planning against this should assume data loss can arrive as a side effect of someone else's cleanup routine. Once that is the assumption, resilience becomes the measure that matters: what can return, and how quickly — which systems make up the minimum viable business.\n\n## Indicators of Compromise\n\nFor inquiries, please contact ti[@]gambit.security. The full public report lists staging IPs, C2 domains, skimmer hosts, and insertion signatures on gambit.security.","body_html":"<h1 id=\"autonomous-ai-agents-are-breaking-into-hundreds-of-online-retail\">Autonomous AI Agents are breaking into hundreds of Online Retailers for $25 a target in an ongoing campaign</h1>\n<p>A financially motivated operator is running three open source AI harnesses against hundreds of online retailers, almost entirely unattended. More than 600,000 credit card records have been taken, and in one case the agent&#39;s own cleanup routine destroyed the victim&#39;s data.</p>\n<p><strong>Eyal Sela</strong> · Director of Threat Intelligence · September 22, 2026</p>\n<p>A financially motivated threat actor is using open source AI harnesses to attack hundreds of online retailers, at a marginal cost of tens of dollars per company. Gambit Security&#39;s Threat Intelligence team recovered the operator&#39;s staging server and reconstructed the campaign from it. Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. The activity goes back to July 2026 and is still running.</p>\n<p>Three AI harnesses ran almost the entire attack chain autonomously, working up to tens of companies a day. The impact we can account for includes at least 600,000 unexpired credit card details from two companies, the installation of card-stealing skimmer scripts on the websites of five, and some level of access to the assets of companies including a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor and a US online fashion retailer. The campaign goes back further, and has impacted at least tens of other companies since July 2026.</p>\n<p>Where access was achieved, it usually took less than a day, and in many cases just a few hours. We also detected instructions in the attacker&#39;s playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent — and this has indeed happened in some of the breaches.</p>\n<p>The following is an interim report of our findings. We base the claim of compromise and impact on three sources. First, direct evidence we found on the attacker&#39;s staging server, such as the exfiltrated data itself and respective tooling. Second, live compromises we verified in the wild — skimmers that have been injected into websites and are still there, or have been removed since but logged in various scanners. Third, logs and AI claims found on the attacker&#39;s server. While AI claims and reporting may turn out to be inaccurate, we rely on them in this report because we could verify substantial parts of the claims by the first two methods, which showed them to be accurate.</p>\n<p>This campaign showcases just how powerful attacks can be in 2026. At very low cost, the AI tools demonstrated a level of patience, persistence, and creativity that most human attackers would be unlikely to sustain in this kind of attack, and achieved far greater results, far faster. Organizations must adapt to a reality where attacks are significantly faster and more comprehensive by shifting to a resilience-first mentality and a security stack that matches the AI speed.</p>\n<p>We have reached out to many of the affected organizations and took measures to take down the infrastructure discovered. We would like to thank the Shadowserver Foundation, Daniel Gordon, and other industry partners for their quick help and availability in notifying impacted organizations, taking down infrastructure, and conducting research.</p>\n<h2 id=\"ai-harnesses\">AI Harnesses</h2>\n<p>The operator used three AI harnesses: <strong>Strix</strong> for vulnerability search, <strong>Cairn</strong> for autonomous end-to-end exploitation, and <strong>Hermes</strong> to orchestrate the campaign, launch intrusion jobs, steer the activity and give tactical guidance in the impact and other stages.</p>\n<p>OpenRouter was used for AI model access. The capture of the account balance on 25 August 2026 records $7,005.71 (US) spent, for a period of four weeks. The operator then ran for three more weeks at about twice the daily volume of model calls, recorded in the agent logs, so the full cost was likely between $12,000 and $18,000. Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company. The operator&#39;s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.</p>\n<h3 id=\"hermes\">Hermes</h3>\n<p>Hermes is an open source autonomous AI agent with a persistent memory, skills that the agent writes and edits itself, a searchable archive of past sessions, scheduled jobs and a web console. On this server it loaded a Chinese system persona titled &quot;SOUL - Red Team Operator&quot;, 121 skills of which 78 were attack skills. The operator also added a skill whose purpose is to remove the content security filters of Hermes itself. Hermes is the operator&#39;s console for orchestrating the activity and for direct hacking activities. It used Anthropic&#39;s opus-4.6 (after newer models refused its requests), with 1,951 prompts typed by the human across 260 sessions — only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.</p>\n<h3 id=\"strix\">Strix</h3>\n<p>Strix is an open source AI penetration testing tool. Between 23 and 31 August 2026 Strix was run 146 times in &quot;deep mode&quot; against 138 hosts, accounting for 633 hours of scanner time in 195 hours of clock time. Some of these reports were the opening of the next stage of the exploitation, handed over to Cairn. Strix ran through OpenRouter on GLM 5.2 and later on DeepSeek v4 Pro.</p>\n<h3 id=\"cairn\">Cairn</h3>\n<p>Cairn is an autonomous penetration testing engine. It receives target domains and an objective, such as to get a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. DeepSeek v4.1 Flash was used in the Cairn attacks.</p>\n<p>Between 10 and 15 September, 105 attack projects were launched. Each attack path was chosen by the harness in real time through extensive probing and exploitation attempts, resulting in dynamic and mostly different TTPs across victims.</p>\n<h2 id=\"target-selection\">Target selection</h2>\n<p>The operator selected targets in several ways. One was a website traffic ranking service, where they chose the shopping category and filtered out the shops running the major hosted or open source commerce platforms, to keep the shops with custom code, which the attacker assumed were more likely to be vulnerable. They then pasted 301 results into the console with a message that ended with instructions to run them via proxy for high-severity findings only. Others were picked by hand or by other means.</p>\n<h2 id=\"exfiltrated-credit-card-data\">Exfiltrated credit card data</h2>\n<p>The threat actor exfiltrated more than 600,000 credit card records from two victim companies. Gambit partnered with Overwatch Data to handle the compromised cards and notify the issuers. The majority of cards (about 79%) were issued in the United States, with the remainder spread across many countries.</p>\n<h2 id=\"database-wipe-after-extraction\">&quot;Database Wipe After Extraction&quot;</h2>\n<p>One of the Hermes agent&#39;s skill files tells the agent to erase the card data from the victim&#39;s Magento database once the data is stolen. The section is called Database Wipe After Extraction and it opens: &quot;After extracting and downloading all card data, wipe the source fields in batches&quot;. At execution time, the operator gave instructions to empty serialized payment columns and to dump tables then clear them. A second victim, a bicycle retailer, lost data when the agent created <code>ZQ</code>-prefixed staging tables and cleanup then dropped 180 tables whose names matched ZQ or Backup, which also impacted backup tables that the victim&#39;s administrators had made.</p>\n<h2 id=\"skimmer-injection-methods\">Skimmer injection methods</h2>\n<p>One of the main objectives of the operator was injecting card-stealing skimmer scripts into the checkout pages of online shops. Skimmers were ordered against at least 27 named victims and confirmed in place on 19 of them during the span of this campaign. With the help of security researcher Varys, Gambit detected more than 100 further websites infected with a skimmer associated with this campaign.</p>\n<p>Methods included: appending loaders to legitimate JavaScript libraries (restoring original timestamps), foreign script tags on checkout pages, injection inside Google tag blocks, S3/CDN poisoning, database content fields, Kubernetes initContainers, server-side page-cache poisoning, and repeating repair tasks that re-append the skimmer after deploys.</p>\n<h2 id=\"what-this-changes\">What this changes</h2>\n<p>This campaign matters more than its size. The tooling is open source and the marginal cost of attacking a company sits in the tens of dollars, so the economics no longer filters anyone out. Where access was achieved it usually took less than a day, and in many cases a few hours, while remediation windows in complex environments are still measured in weeks. The harnesses ran at a tempo no human operator sustains, with the person reduced to short instructions between autonomous runs.</p>\n<p>The practical consequence is a remediation clock most organizations cannot hold. Organizations planning against this should assume data loss can arrive as a side effect of someone else&#39;s cleanup routine. Once that is the assumption, resilience becomes the measure that matters: what can return, and how quickly — which systems make up the minimum viable business.</p>\n<h2 id=\"indicators-of-compromise\">Indicators of Compromise</h2>\n<p>For inquiries, please contact ti[@]gambit.security. The full public report lists staging IPs, C2 domains, skimmer hosts, and insertion signatures on gambit.security.</p>","headings":[{"level":1,"text":"Autonomous AI Agents are breaking into hundreds of Online Retailers for $25 a target in an ongoing campaign","id":"autonomous-ai-agents-are-breaking-into-hundreds-of-online-retail"},{"level":2,"text":"AI Harnesses","id":"ai-harnesses"},{"level":3,"text":"Hermes","id":"hermes"},{"level":3,"text":"Strix","id":"strix"},{"level":3,"text":"Cairn","id":"cairn"},{"level":2,"text":"Target selection","id":"target-selection"},{"level":2,"text":"Exfiltrated credit card data","id":"exfiltrated-credit-card-data"},{"level":2,"text":"\"Database Wipe After Extraction\"","id":"database-wipe-after-extraction"},{"level":2,"text":"Skimmer injection methods","id":"skimmer-injection-methods"},{"level":2,"text":"What this changes","id":"what-this-changes"},{"level":2,"text":"Indicators of Compromise","id":"indicators-of-compromise"}]}}