Skip to content

Security1 publisher2 min readPublished

One operator ran 105 AI-driven attack waves in five days at about $25 a company

Gambit says a single actor pointed the Strix, Cairn and Hermes agent frameworks at online retailers from July onward, taking more than 600,000 valid card records from two victims and leaving skimmers on 119 sites.

The Watch · Security desk

Illustration accompanying One operator ran 105 AI-driven attack waves in five days at about $25 a company

What happened

  • Gambit says a financially motivated actor has been using open-source AI agent frameworks to attack hundreds of online retailers at scale, taking more than 600,000 credit card records.
  • The campaign has run since at least July and was still active on September 22, according to the researchers.
  • In one five-day stretch the actor launched more than 100 attacks and compromised at least 27 companies.
  • At least 119 websites carry the skimmer, and the victims include a Fortune 500 hospitality company, a major U.S. airline, a large U.S. industrial supplies distributor and an online fashion retailer.
  • An OpenRouter account tied to the operation showed $7,005.71 spent in roughly four weeks to August 25; Gambit puts the full campaign at $12,000 to $18,000, about $25 per target.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost The cheapest completed scan cost $3.13, so spend no longer decides which companies get looked at: a mid-size retailer sits in the same queue as the airline.
  • exposure The wipe step turns a card breach into a data recovery job for the victim, because the agent deletes the source fields in the retailer's own Magento database after exfiltrating them.
  • constraint Cron-based reinstallation means pulling the skimmer off a checkout page is not remediation; whoever cleans without finding the scheduler will be cleaning again.
  • capability One person issuing short goal statements between autonomous runs sets the pace, so attacker head-count stops predicting the attack volume a defender has to absorb.

Each tool had one job. Strix handled discovery, running 146 times against 138 hosts between August 23 and 31 and accumulating 633 scanning hours [8]. Cairn took objectives such as obtaining a shell or admin access and worked them autonomously [6]. Hermes ran the campaign: orchestration, tactical decisions, post-exploitation, directed by claude-opus-4.6 [7]. Its skill library held 121 entries, 78 of them attack-related, under a persona called "SOUL - Red Team Operator" [9].

Those 633 hours sit inside a nine-day window containing 216 hours of wall clock, so Strix averaged close to three scans running at once, continuously [1].

Gambit says the operator fed the Strix output through a website traffic-ranking service and prioritized companies running custom software, on the assumption that custom code was likelier to be vulnerable [15]. Skimmer delivery then varied with whatever access Cairn won: code appended to legitimate JavaScript files, script tags added to checkout pages and Google tag blocks, poisoned S3/CDN content and server-side caches, modified database fields, altered Kubernetes deployments [12].

The card theft was concentrated. Two companies produced the entire haul, and five other organizations had skimmers planted on their sites to collect payment data [4].

One Hermes skill file carries the cleanup step: "After extracting and downloading all card data, wipe the source fields in batches" [17]. The researchers found that instruction pointed at Magento databases after exfiltration [16], and say the data loss caused operational disruptions at several retailers [18]. Their advice to defenders is to plan for losing their own records as a side effect of the attacker's housekeeping [24].

On spend, Gambit wrote: "The operator's own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive" [22]. Divide the top of the researchers' total estimate by the card count and each stolen record cost about three cents in inference [3].

The 27 companies that fell came out of 105 distinct waves, so roughly one in four attempts landed to some degree [11][2]. Gambit also says access was often obtained within a few hours, with the operator supplying short instructions between autonomous runs [23].

The evidence comes from inside the operation: Gambit researchers gained access to the attacker's staging server and retrieved direct evidence [13]. All of it is one startup's investigation, and the account describes the human operator only as appearing to be Chinese, briefing the agents on goals and leaving them to it [10].

What to watch

  • Whether a second research team or a payment brand corroborates the campaign independently of Gambit's staging-server access.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories