📣 Send us your press release
Site updates every 15 minutes
Technology

AI Agents Used in Large-Scale Credit Card Theft Campaign

A threat actor utilized autonomous AI agents to compromise online retailers and harvest over 600,000 credit card records within a five-day period.

29 September 2026
AI Agents Used in Large-Scale Credit Card Theft Campaign

Cybersecurity firm Gambit Security has uncovered a significant cyberattack campaign where threat actors employed autonomous AI agents to compromise online retailers and steal sensitive customer data. Over a five-day span in September 2026, the operation resulted in the theft of more than 600,000 credit card records from at least 27 businesses.

The campaign, which had been ongoing since July 2026, operated largely unattended. It leveraged a combination of open-source AI frameworks: Strix for vulnerability discovery, Cairn for dynamic attack execution, and Hermes for orchestrating the overall operation. These systems utilized various AI models, including DeepSeek and Claude Opus, to automate the attack chain.

Operational costs for the campaign were notably low, estimated at approximately $8,000 for the five-day period, averaging $25.46 per target. The stolen credit card data primarily originated from the United States, but also included records from numerous other countries worldwide.

Beyond data theft, the attackers also deployed payment skimmers on checkout pages and executed destructive data deletion routines that inadvertently wiped out the victims' own backup tables. The methods used to inject these malicious elements varied depending on the targeted systems' technology stacks.

This incident highlights the increasing role of AI in cybercrime and demonstrates how accessible tools and low costs are lowering the barrier for sophisticated attacks, posing a growing threat to businesses globally.

Original source: gamblersconnect.com