The Pulse
Gambit Says AI Agents Stole 600,000 Retail Card Records
Gambit Security says an attacker used three AI harnesses to target hundreds of online retailers. Its September 22 report attributes more than 600,000 stolen credit-card records to two companies and documents skimmer infections and destructi

AI.info Team ·
Gambit Security says a financially motivated attacker used AI tools to steal more than 600,000 credit-card records from two online retailers, while targeting hundreds of other shops. The company published its interim findings on September 22, 2026, after recovering what it described as the operator’s staging server. Gambit says the campaign began in July and remained active during its investigation.
Three tools divided the attack work
According to Gambit, the operator combined Strix to search for vulnerabilities, Cairn to carry out exploitation, and Hermes to coordinate operations and provide direct hacking assistance. The tools handled much of the chain with limited human direction, though logs show the operator issued short prompts in Chinese across hundreds of sessions. Gambit says an account snapshot showed $7,005.71 in model-access charges over four weeks; its estimate for the full campaign’s AI costs is $12,000 to $18,000.
The sequence produced 105 attack projects between September 10 and 15, Gambit reports. At least 27 companies were compromised to varying degrees during that period. The firm says it could examine 48 project reports; the other 57 had been deleted. Its account of the campaign draws on stolen data and tools found on the server, verified live or recorded website infections, and logs that include AI-generated claims—some of which, it cautions, could be inaccurate.
Stolen cards and checkout skimmers
Gambit says it found more than 600,000 unexpired card records taken from two companies. Its breakdown, prepared with fraud firm Overwatch Data, counts 488,372 cards issued in the United States, or 79 percent of the total. The companies are not named in the report. Gambit says it worked with Overwatch Data to handle the compromised cards and notify issuers.
The campaign also aimed to plant scripts that steal payment details from checkout pages. Gambit confirmed skimmers on 19 sites among named targets and, working with security researcher Varys, found more than 100 additional infected websites associated with the campaign. The firm describes several routes into store pages, including modified JavaScript files, cloud storage, database content and Kubernetes deployment settings.
Cleanup instructions caused damage
Recovered Hermes files contained instructions for deleting card data from a Magento database after extraction. One section began: “After extracting and downloading all card data, wipe the source fields in batches.” Gambit also says a separate cleanup operation at a bicycle retailer dropped 180 tables, including backup tables created by the victim’s administrators.
The report is an interim account, not a complete tally of the victims. Gambit says its evidence supports the compromises it describes but acknowledges that the scale and incomplete records leave room for errors; it estimates the campaign’s actual impact may be larger. The documented findings already include stolen records, skimmer infections across more than 100 websites, and a cleanup routine that erased data belonging to a victim.