Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Agents Exploit Retailers, Steal 600,000 Credit Cards

AI Agents Exploit Retailers, Steal 600,000 Credit Cards

Posted on September 22, 2026 By CWS

AI Agents Target Retailers

Autonomous AI agents have been implicated in a major cybercrime operation, targeting online retailers and stealing over 600,000 credit card details. Utilizing open-source AI tools, the operator managed this attack with minimal oversight. These AI-driven scripts infiltrated numerous checkout pages, extracting sensitive card information and, in some cases, erasing critical victim data.

The Economic Impact of AI-driven Cyber Attacks

The financial implications of this campaign highlight a worrying trend. Between August and September 2026, the operator invested approximately $12,000 to $18,000 for AI model access via OpenRouter, with costs per target averaging just $25.46. This low-cost barrier has enabled less skilled attackers to execute highly effective attacks that previously required significant resources.

The attack campaign, decoded by Gambit Security’s Threat Intelligence team, has exposed vulnerabilities across various sectors. This operation, ongoing since July 2026, demonstrates how AI tools can amplify attack capabilities and evade traditional security measures.

AI Tools in Action: A Coordinated Effort

According to Gambit Security’s research, the campaign utilized three key AI tools: Strix, Cairn, and Hermes. Strix was responsible for identifying vulnerabilities autonomously, while Cairn executed prolonged exploitation attempts to gain system access. Hermes, the orchestrator, coordinated these activities, providing guidance and launching attacks.

During a short period in late August, Strix conducted 146 intensive scans, exploiting host vulnerabilities at a pace unmatched by human teams. Operator involvement was minimal, with brief directions given to Hermes in Chinese, showcasing the potential for AI to execute attacks with little human input.

A Detailed Look at the Attack Timeline

Between September 10 and 15, Cairn initiated 105 attack projects, compromising at least 27 companies to varying extents. Each intrusion was meticulously planned in real-time, adapting tactics based on target defenses. Some attacks began with SQL injections, escalating to full access through misconfigured systems and culminating in sensitive data extraction.

Two victims accounted for the majority of stolen card records, with anti-fraud firm Overwatch Data validating the theft of 600,000 card details, primarily belonging to US cardholders. The freshness of the data, with 60% previously unflagged for fraud, emphasizes the sophistication of the operation.

Future Outlook and Security Implications

This campaign underscores a critical shift in cybersecurity landscapes. With open-source tools and low operational costs, threat actors can orchestrate complex attacks rapidly. The accessibility of these tools means that security measures must evolve to address the rapid pace of AI-driven threats.

Gambit Security has notified affected entities and collaborated with organizations like the Shadowserver Foundation and Cloudflare to dismantle the operation’s infrastructure. Despite these efforts, the operator has persistently rebuilt their systems, indicating the ongoing challenge of combating such advanced threats.

As cyber threats continue to evolve, organizations must adopt robust detection and response strategies to mitigate the risks posed by autonomous AI agents.

Cyber Security News Tags:AI security, AI tools, autonomous agents, Cairn AI, credit card theft, cyber attack, Cybercrime, cybersecurity threats, data breach, fraud prevention, Gambit Security, Hermes AI, online security, retail security, Strix AI

Post navigation

Previous Post: Malicious NPM Package Threatens Supply Chain Security

Related Posts

GitGuardian Secures M to Enhance AI and Security Solutions GitGuardian Secures $50M to Enhance AI and Security Solutions Cyber Security News
Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files Cyber Security News
Linux Kernel 6.18-rc1 Released With Extensive Updates Following a Steady Merge Window Linux Kernel 6.18-rc1 Released With Extensive Updates Following a Steady Merge Window Cyber Security News
Hackers Weaponize SVG Files and Office Documents to Target Windows Users Hackers Weaponize SVG Files and Office Documents to Target Windows Users Cyber Security News
DuckDuckGo Introduces Built-In YouTube Ad Blocking DuckDuckGo Introduces Built-In YouTube Ad Blocking Cyber Security News
New N0va Phishkit: Emerging Threat to North America and EU New N0va Phishkit: Emerging Threat to North America and EU Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark