AI

AI-Powered Campaign Allegedly of Chinese Origin Steals Over 600,000 Payment Records

According to Gambit researchers, a campaign carried out with autonomous AI agents since July 2026 has led to the theft of at least 600,000 payment records and is still active. It is stated that the attackers compromised numerous retail sites using three AI frameworks at an average cost of $25 per target.

Elias KorhonenElias Korhonen4 min read
Share
AI-Powered Campaign Allegedly of Chinese Origin Steals Over 600,000 Payment Records

According to a statement from security researchers at Gambit, a card skimming campaign running since July 2026 and carried out with autonomous AI agents has targeted numerous retail sites worldwide, leading to the theft of at least 600,000 payment records. According to the company's statement, the attack is still active and attacks on websites continue as part of the campaign.

Researchers managed to reconstruct the operation of the campaign by seizing the staging server used by the attackers. It was stated that skimmers on victim sites were observed live, and records on the server and data belonging to AI agents were examined. According to Gambit, during a five-day period between September 10-15, the agents launched 105 attack waves and compromised 27 organizations at "varying levels."

Victims include major companies

According to Gambit's statement, the victims include a Fortune 500 hospitality company, a "major" U.S. airline, a large private-sector industrial materials distributor, and a U.S. online fashion retailer. It was stated that one of the AI tools created a target list by using a website ranking service and primarily targeted sites using custom software.

Cost per target is a few dollars

Researchers assess that the attackers are Chinese threat actors seeking financial gain. According to the company's statement, the attackers use three AI "harnesses" capable of autonomously executing nearly the entire attack chain and target approximately 10 companies per day.

It was stated that approximately $7,000 was spent in four weeks, and the total cost of the operation to date has not exceeded $18,000. According to figures reported by Gambit, this means an average of $25.46 per target; $3.13 for the cheapest target and $79.31 for the most expensive target. Researchers noted that in cases where access was achieved, it generally took less than a day, and in most cases only a few hours.

According to the statement, the attackers' playbook also includes instructions that could disrupt a company's operations as a result of the agent running data deletion or wiping procedures, and this actually occurred in some breaches.

Three AI frameworks: Strix, Cairn, and Hermes

The three harnesses used in the campaign are named Strix, Cairn, and Hermes. According to Gambit's statement, Hermes is an open-source autonomous AI agent with persistent memory, self-authored and edited skills, past sessions kept in a searchable archive, and the ability to execute scheduled tasks.

On the examined server, it was stated that Hermes loaded a Chinese system persona named "SOUL - Red Team Operator" containing 121 skills (78 attack skills). According to the company, Hermes used Anthropic's opus-4.6 model because newer models refused requests; in 260 sessions, 1,951 prompts were written by humans, amounting to only a few prompts per target. It was stated that these prompts were generally short Chinese instructions that initiated the attack, determined the agent's next step, or told it what to do after gaining access.

Strix is described as an open-source AI penetration testing tool, while Cairn is described as an autonomous penetration testing engine. According to Gambit's statement, Cairn takes target domains and an objective such as obtaining shell or admin access and works for hours until it achieves that objective, times out, or is stopped; this tool used the DeepSeek v4.1 Flash model.

Call for defense from researchers

Gambit researchers stated that the campaign is very low-cost and has reached a level of patience, persistence, and creativity that "most human attackers would be unlikely to sustain."

The company called on organizations to adapt to a reality in which attacks have become significantly faster and more extensive. For this, it recommended adopting an approach that prioritizes resilience and deploying a security infrastructure that can keep up with the speed of AI. It was stated that most affected organizations were notified and the skimmers were removed.

Share

You May Also Like

Comments (0)

Log in or sign up to leave a comment.

No comments yet. Be the first!