AI agents stole 600,000 credit cards for about $25 a target, Gambit says

Credit: rupixen on Unsplash An attacker used three open-source AI agent frameworks to break into at least 27 companies and steal more than 600,000 credit card records, security company Gambit says. The victims include a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor and a US online fashion retailer. Eyal Sela, Gambit’s director of threat intelligence, set out the findings in a report published on 22 September. Gambit recovered the attacker’s staging server and rebuilt the campaign from its logs, the stolen data and compromises it verified on live sites.

TNW has not independently verified the findings. Three agents, four models Strix, an open-source penetration testing tool, scanned targets for weaknesses. It ran on Z.ai’s GLM 5.2 and later on DeepSeek V4 Pro. Cairn, an autonomous penetration testing agent, carried out attacks from start to finish on DeepSeek V4.1 Flash.

Hermes ran the campaign and also hacked targets directly, using Anthropic’s Claude Opus 4.6. It held 121 skills, 78 of them for attacks. The human operator typed 1,951 prompts across 260 sessions, which Gambit says came to only a few prompts per target. The operator reached the models through OpenRouter. “Where access was achieved, it usually took less than a day, and in many cases just a few hours,” Sela wrote.

About $25 a scan The operator’s OpenRouter account spent $7,005.71 over four weeks. Gambit estimates the whole campaign cost $12,000 to $18,000. A completed scan cost $25.46 on average, and between $3.13 and $79.31. The campaign began in July.

Between 10 and 15 September alone, the operator launched 105 attack projects and compromised at least 27 companies. Gambit confirmed card skimmers at 19 of the named victims and found skimmers on more than 100 other websites. The 600,000 cards came from two companies, and 79% belonged to US cardholders. The skimmers hid in JavaScript libraries such as jQuery, in Google tags and in Kubernetes containers.

At one US wine retailer, a cron job put the skimmer back every two minutes after the site was redeployed. Prompts in Chinese, and deleted backups The staging server loaded a system persona called “SOUL – Red Team Operator”, and the operator typed short instructions in Chinese. Gambit does not tie the campaign to any named group or country. The agents’ cleanup routines also destroyed data.

At a bicycle retailer, they dropped 180 database tables, including backups the victim’s own administrators had made. Gambit said it contacted many of the affected organisations and helped take down the infrastructure, with help from the Shadowserver Foundation. Overwatch Data is handling fraud reporting to card issuers. AI agents and security The report adds to a run of incidents involving AI agents.

OpenAI took about 2.5 hours to stop an agent that escaped its sandbox, and OpenAI agents attacked RubyGems in May. Anthropic’s own threat intelligence report this month detailed how Claude was misused for surveillance and weapons.

Leave a Reply

Your email address will not be published. Required fields are marked *