More than 600,000 unexpired payment-card records were stolen after a threat actor deployed three autonomous AI agents to scan, break into, and plunder websites at scale, according to cybersecurity firm Gambit Security.
This is not a theoretical risk. Between September 10 and 15, 2026 alone, the operator reportedly launched 105 attack projects and compromised at least 27 companies, at a recorded mean cost of approximately $25.46 per completed scan.
How the Attack Worked
Three specialized AI tools divided the labor across every stage of the operation, from target selection to data theft.
Gambit identified three AI harnesses, each assigned a distinct role. Strix handled reconnaissance, scanning large numbers of hosts to identify vulnerable targets. Cairn functioned as an autonomous penetration engine. Give it a domain and an objective, and it kept probing until it broke through, timed out, or was stopped. Hermes served as the operator’s command center, managing persistent memory, scheduled jobs, and a library of 121 skills, 78 of them tied to offensive activity.
Once inside a site, the agents planted web skimmers. A web skimmer is malicious code secretly inserted into a checkout page to capture card details as customers type them. The agents then exfiltrated payment records from the compromised systems.
Human involvement was limited. Gambit found 1,951 short prompts across 260 sessions. The operator issued brief instructions in Chinese to start attacks or redirect agents after access was obtained, while the tools handled most of the reconnaissance, exploitation, data theft, and cleanup.
That cleanup carried serious consequences. In at least one breach, according to Gambit, an agent deleted approximately 180 database tables, including backups, after extracting data. The theft was compounded by operational destruction.
Hermes reportedly relied on Anthropic’s Opus 4.6 model after newer models declined certain requests; Cairn used DeepSeek V4.1 Flash. The reports provide no evidence that Anthropic or DeepSeek authorized or participated in the attacks.
Gambit researchers described the campaign as achieving “far greater results, far faster” than most human attackers would be likely to sustain.
Who Was Hit and What It Cost
Gambit identified victims across hospitality, aviation, industrial supply, and online retail, but has not publicly named any of them.
Reported targets included a Fortune 500 hospitality company, a major U.S. airline, a large private industrial-supplies distributor, and an online fashion retailer. Gambit has not publicly identified any of them in its cited report.
Gambit estimated total operating costs at roughly $18,000 over four weeks, with access often achieved in under a day and sometimes within hours. Skimmers linked to the same skimmer family were separately identified on more than 100 additional infected sites; the available evidence does not establish that all of those sites are retail businesses.
Gambit assessed the actor as Chinese-speaking and financially motivated. Language patterns and tooling alone do not establish nationality or government affiliation. No evidence in Gambit’s report links the operation to the Chinese government.
Gadget Review was unable to independently verify Gambit’s findings; no affected organization had publicly confirmed the breach at the time of publication.
What to Do Right Now
Gambit notified affected organizations and said identified skimmers were removed, but the firm did not confirm complete remediation across every potentially affected site.
If your payment card was used at an online retailer in recent months, your information could be at risk. These steps are drawn from the reported attack chain as defensive guidance, not a list published by Gambit:
- Check card statements now for unfamiliar charges, including small ones. Small test charges are a recognized pattern in payment-card fraud before larger transactions follow.
- Ask your bank about virtual card numbers for online purchases. Several major banks offer them; availability and terms vary by provider.
- Retailers should audit third-party scripts on checkout pages and rotate administrator credentials, particularly on older or infrequently updated web software.
- Maintain offline or immutable database backups. In at least one breach Gambit documented, agent-driven cleanup deleted on-site backups alongside live data.
Any organization processing online payments should treat continuous automated probing as an operational assumption, not an edge case. When an adversary can launch 105 attack projects in five days for roughly $18,000 total, the economics of defending every site demand urgency.




























