Cybersecurity startup Gambit uncovered a campaign ongoing since July 2026 in which a financially motivated attacker uses open-source AI agent frameworks to attack online stores at scale. According to findings published on September 23, more than 600,000 valid card records were stolen from two companies, while payment-data skimming malware was planted on at least 119 sites.
In just five days, the attacker carried out more than 100 attacks, with varying degrees of success against at least 27 companies. The targets included a hospitality company listed in the Fortune 500, a major U.S. airline, a large industrial distributor in the United States, and an online fashion retailer.
Three Agents to Execute the Attack Chain
The operation relied on three tools. Strix was used to scan hosts and discover vulnerabilities, while Cairn handled objectives such as obtaining a terminal session or administrator privileges. Hermes coordinated the campaign, post-compromise activities, and tactical decision-making, using the Claude Opus 4.6 model.
Strix ran 146 times against 138 hosts between August 23 and 31, for a total of 633 hours of scanning. Hermes also contained a persona named “SOUL - Red Team Operator” and 121 skills, 78 of which were attack-related. The researchers said that the human operator, believed to be Chinese, briefly specified targets and then left the agents to carry out the rest of the operations.
Multiple Methods for Planting Skimming Malware
The method of planting the malware varied according to the level of access, vulnerabilities, and site architecture. Techniques included modifying legitimate JavaScript files, adding tags to payment pages or Google Tag blocks, poisoning S3 content and CDN and server-side caches, modifying database fields, altering Kubernetes deployments, and creating cron jobs that restored the malware after its removal.
Gambit researchers were able to access an attacker test server, where they found instructions for the Hermes agent to delete card-data fields from Magento databases after extracting and downloading them. This action resulted in data loss and operational disruptions at several stores, adding a destructive impact alongside the data theft.
What Changes in Practice?
The campaign shows that agents do not need detailed human instructions to execute a lengthy attack chain, and that lowering the cost of scanning and exploitation may make it possible for less experienced attackers to target dozens of companies per day. Gambit observed an OpenRouter account spend $7,005.71 over approximately four weeks through August 25, and estimated the operation's total cost at between $12,000 and $18,000, averaging approximately $25 per target. The average calculated across 101 completed scans ranged from $3.13 to $79.31.
Accordingly, protection is not limited to detecting skimming code or closing the vulnerability; organizations operating websites should also account for the possibility of database modification, tampering with CDN and S3 resources, and malware persistence through scheduled tasks. The source confirms widespread theft and disruptions among some victims, but does not provide complete details about all affected companies or the method used to compromise each target.