A financially motivated threat actor has weaponized open-source AI agents to breach hundreds of online retailers, spending as little as $25 per target while extracting more than 600,000 credit card records in an ongoing campaign that began in July 2026.
Gambit Security’s Threat Intelligence team recovered the operator’s staging server and reconstructed the operation, finding that between September 10 and 15 alone, the operator launched 105 attack projects, compromising at least 27 companies to varying degrees.
The operator relied on OpenRouter for AI model access, spending $7,005.71 over four weeks before doubling daily volume, pushing total campaign costs to an estimated $12,000–$18,000.
Autonomous AI Agents Hack Online Retailers for $25 a Target
Averaged across targets, this works out to a mean of $25.46 per completed scan, ranging from $3.13 to $79.31. Where access succeeded, it typically took less than a day, often just hours.
The operator chained together three open-source tools. Strix, an AI penetration testing tool, ran 146 scans against 138 hosts using GLM 5.2 and DeepSeek v4 Pro to surface vulnerabilities.
Cairn, an autonomous exploitation engine powered by DeepSeek v4.1 Flash, took vulnerability reports and objectives, then ran unattended for hours until achieving shell or admin access.

Hermes, running on Anthropic’s opus-4.6, served as the human-facing orchestration console, loaded with a red-team persona and 78 attack skills, requiring only short Chinese-language prompts to steer each intrusion.
Victims included a Fortune 500 hospitality company, a major US airline, an industrial supplies distributor, and a fashion retailer.
Exfiltrated card data, analyzed with fraud specialist Overwatch Data, showed 79% of the 600,000-plus records were US-issued, with smaller shares from the UAE, Saudi Arabia, the UK, and dozens of other countries.
Notably, one of Hermes’s own skill files instructed the agent to wipe stolen card fields from Magento databases after extraction.
In one confirmed incident, this “wipe-after-extraction” logic combined with overly broad table-name matching to drop 180 tables at a bicycle retailer, destroying victim-created backups in the process.

Skimmers were deployed against at least 27 named victims and confirmed active on 19, with over 100 additional infected sites identified through partner research.
Injection methods varied by environment: appending loader code to legitimate JavaScript libraries, inserting foreign script tags on checkout pages, hiding payloads inside Google tag blocks, poisoning S3-backed CDN buckets, and even planting a self-repairing cron job that restored the skimmer every two minutes after redeployments wiped it out.
The campaign underscores that low-cost, largely unattended AI agents can now compromise enterprise retailers faster than most human-driven remediation processes can respond.
With roughly 87% of exploited vulnerabilities attacked on or before public disclosure, according to a16z research cited in the report, organizations can no longer rely on patch speed alone.
Security teams are being urged to shift toward resilience-first planning, identifying the minimum viable systems needed to keep revenue flowing and verifying recovery works even when data loss stems from an attacker’s own automated cleanup rather than intentional destruction.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team