Spending just US$8,000 for the use of autonomous AI agents, the hacker compromises 27 firms, steals more than 600,000 payment-card records
According to Gambit Security, a Chinese-speaking hacker reportedly used autonomous AI agents to attack as many as 100 online retailers and steal more than 600,000 payment-card records.
The operation was described by one researcher as among the most serious known cases of AI being used to conduct large-scale exploitation.
The firm discovered the campaign after the attacker mistakenly left the servers supporting the operation accessible on the public internet. The exposed infrastructure reportedly contained stolen data, the AI tools used in the attacks, and prompts that showed how the intrusions were directed. The hacker had spent about US$8,000 on access to AI models and related services.
Modus operandi
The campaign relied on three open-source AI orchestration systems.
- Strix performed vulnerability scans
- Cairn managed the exploitation process until it obtained shell or administrator access
- Hermes coordinated the overall operation while giving the agents tactical instructions
The systems used models from DeepSeek and Kimi, as well as Anthropic’s Claude Opus 4.6. Attempts to use newer Claude models were reportedly blocked, suggesting that their updated safeguards detected and refused the criminal activity.
Human involvement was limited. During 260 Hermes sessions, the operator entered only 1,951 commands, most of them short Chinese instructions such as “read the vulnerability report and start.” Across 101 completed scans, the average cost per target was US$25.46, with individual operations ranging from US$3.13 to US$79.31.
From 10 to 15 September 2026, investigators confirmed that at least 27 firms had been compromised to different degrees. The victims included:
- A Fortune 500 hospitality company
- A major US airline
- A large industrial-supplies distributor
- An online fashion retailer
Payment-card skimmers were verified on 19 identified victims and associated with more than 100 other sites. Overwatch Data has confirmed that the 600,000-plus records were unique and legitimate; about 488,000 involved US cardholders. A payment processor also found that at least 60% of a sampled group had not previously been marked as fraudulent.
Notably, the AI agents’ cleanup routines caused additional damage in at least two incidents by deleting victims’ data, including backup tables. Anthropic has said it has banned the account linked to the attacks. Gambit has notified affected organizations and worked with Cloudflare and the Shadowserver Foundation to disable the attacker’s infrastructure, but the hacker repeatedly rebuilt the servers, indicating that the campaign may still be active.
