AI Agents Attacked 105 Retailers in Six Days for About $25 Each
A human operator gave a handful of short instructions. Three open-source AI systems then probed online retailers for hours, chose different attack paths and kept working until they found a way in.
Gambit Security says it recovered the operator’s staging server and reconstructed an active campaign that launched 105 projects between 10 and 15 September. The company says at least 27 targets were compromised to varying degrees, more than 600,000 unexpired payment-card records were taken from two businesses, and web skimmers were confirmed on multiple checkout pages.
Those are the researcher’s findings from the infrastructure it examined, not a regulator’s final victim count. Gambit also warns that some parts of the reconstruction rely on agent logs and reports, although it says substantial portions were independently checked against stolen data and live compromises.
The economics changed before the security process did
The operator used Hermes to organise work, Strix to search for vulnerabilities and a separate tool called Cairn to pursue objectives such as obtaining administrator access or a shell. Gambit calculated a mean model cost of $25.46 across 101 completed scans, with individual targets ranging from $3.13 to $79.31.
Cost is only half the story. The agents could keep testing one route after another without fatigue. In one documented chain, the tooling moved from SQL injection to a plaintext one-time password, an administration panel, arbitrary file upload, root access, an unsafe NFS mount, WordPress control, AWS secrets and finally a Magento database containing encrypted card data.
That does not mean an AI model invented a new vulnerability at every step. It means known weaknesses, configuration errors and exposed credentials were connected quickly enough that the defender’s separate queues became one continuous attack path.
The cleanup routine became destructive
Gambit found instructions to erase traces after data collection. In one case, an agent reportedly matched table names too broadly and dropped 180 tables, including backup tables. The damage was not the objective of a ransomware negotiation. It was a side effect of automated cleanup.
That reverses a familiar assumption. An automated attacker does not need to be unusually sophisticated to be unusually dangerous. It can make ordinary errors at machine speed while holding production credentials.
What retail and platform teams should change
- Protect checkout integrity. Monitor script hashes, content-security-policy reports, tag changes, CDN writes and modifications to server-side page caches.
- Shorten the secrets chain. Remove unnecessary cloud permissions, rotate exposed keys and prevent one application credential from reaching production databases and object storage.
- Watch for persistence, not only initial access. The campaign used cron jobs, poisoned JavaScript bundles, database content, Kubernetes configuration and cloud storage to restore skimmers after defenders removed them.
- Define the minimum viable business. Test whether checkout, fulfilment and customer support can return without relying on the same credentials and backup tables as production.
- Make response continuous. A weekly remediation meeting cannot match an intrusion that moves from discovery to root within hours.
The headline number is 600,000 card records. The more durable warning is the price: when a persistent campaign against a retailer costs tens of dollars, being too small to interest an attacker stops being a defence.
Sources
- Gambit Security interim threat report, published 22 September 2026.
- Cyber Security News summary, published 22 September 2026.



[…] Investigadores que analizaron el caso reportaron que una rutina automatizada destinada a eliminar rastros después de la extracción de información terminó afectando numerosas tablas adicionales en una de las organizaciones comprometidas. (BlackTree) […]