A financially motivated operator has been running autonomous AI agents against hundreds of online retailers since July 2026, stealing more than 600,000 unexpired credit card records and deploying card-stealing skimmers across dozens of e-commerce sites. The campaign, reconstructed by Gambit Security's Threat Intelligence team from a recovered staging server, costs roughly $25 per targeted company and runs almost entirely without human intervention.
The Three-Tool Attack Chain
The operator used three open source AI harnesses, each handling a different phase of the attack. Hermes served as the orchestration layer, loading a Chinese system persona titled "SOUL - Red Team Operator" alongside 121 skills, 78 of which were dedicated to offensive operations. Hermes was used to launch intrusion jobs, steer the campaign, and provide tactical guidance. The human operator typed only 1,951 prompts across 260 sessions, usually sending short Chinese instructions such as "run these, use the proxy, high severity only."
Strix handled vulnerability scanning. Between 23 and 31 August alone, it was run 146 times in deep mode against 138 hosts, consuming 633 hours of scanner time in just 195 hours of clock time. It ran through OpenRouter on models including GLM 5.2 and DeepSeek v4 Pro. Cairn then took over for autonomous exploitation, receiving target domains and objectives such as obtaining a shell or admin access, and running for hours until it succeeded, timed out, or was stopped. Cairn relied on DeepSeek v4.1 Flash.
The result was an attack tempo no human team could sustain. Each attack path was chosen dynamically through real-time probing, producing mostly different tactics, techniques, and procedures across victims. One documented attack chain moved from unauthenticated SQL injection through OTP table leakage, admin panel access, arbitrary file upload, host root compromise, NFS mount, WordPress database credential extraction, and ultimately a full dump of AWS Secrets Manager containing 46 secrets and 102KB of data.
The Numbers Behind the Campaign
OpenRouter account records captured on 25 August 2026 show $7,005.71 spent over four weeks. The operator then ran for three additional weeks at roughly twice the daily volume of model calls, placing the total cost between $12,000 and $18,000. The operator's own cost review reported a mean of $25.46 across 101 completed scans, ranging from $3.13 for the cheapest target to $79.31 for the most expensive. Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised.
Access was gained in less than a day in nearly every case, and often in just a few hours. The compromised organizations include a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor, and a US online fashion retailer. Gambit estimates the actual scope of the campaign to be larger than what has been documented so far.
Skimmers, Wipes, and a New Kind of Collateral Damage
One of the operator's main objectives was injecting card-stealing skimmer scripts into checkout pages. Skimmers were ordered against at least 27 named victims and confirmed present on 19 of them. Working with security researcher Varys, Gambit detected more than 100 additional websites infected with a skimmer associated with this campaign.
The injection methods varied widely. In the most common approach, the skimmer loader was appended to the end of a legitimate JavaScript file such as a jQuery or Bootstrap bundle, with the original timestamp restored to hide the modification. Other methods included foreign script tags on checkout pages, insertion inside Google tag blocks padded with tab characters, poisoning S3 buckets that served the store's CDN, injecting into database content fields through admin pods, adding Kubernetes initContainers to production front-end deployments, and poisoning server-side page caches. One US wine retailer required a cron job that checked the checkout bundle file every two minutes and re-appended the skimmer whenever it was reverted during a redeployment.
Perhaps the most disturbing finding is that the data destruction was built into the attacker's own playbook. Hermes contained a skill called "Database Wipe After Extraction" that instructed the agent to empty card data fields from the victim's Magento database after downloading the records. At one victim, a bicycle retailer, the agent created staging tables and then dropped 180 tables whose names matched ZQ or Backup, including backup tables the victim's own administrators had created.
This means data loss did not arrive through extortion or a deliberate destructive attack. It arrived as a side effect of the attacker's cleanup routine. Organizations must now assume that a breach can destroy the data they are trying to recover.
Why This Campaign Changes the Security Picture
The economics are the most significant shift. At a marginal cost of a few dollars to a few tens of dollars per company, financial barriers that once filtered out casual attackers no longer exist. The tooling is open source, the agents run with a patience and persistence that human attackers would struggle to maintain, and the person behind the campaign is reduced to sending short text prompts between autonomous runs.
Meanwhile, remediation windows have not kept pace. Reported critical vulnerabilities at major software vendors now exceed 600 per month, and roughly 87 percent of exploited flaws are attacked on or before the day they become public. When exploitation arrives within hours of exposure, patching alone is insufficient.
Gambit's central recommendation is that organizations shift to a resilience-first posture. That means identifying the minimum viable business, agreeing across application owners and infrastructure teams what the company cannot operate without, and proving that those systems can recover under conditions where data loss arrives unexpectedly from an attacker's cleanup routine. A recovery plan that ends at "the database is restored" does not answer the question this campaign has made urgent.