Sev0

AI security incidents, tracked

All incidents / AI-run attack

Attacker used open-source AI agent frameworks to plant card skimmers on retail sites

Multiple, disclosed 22 Sep 2026 AI-run attack Exposed and destroyed High

What happened

Gambit Security reported a financially motivated operator who used the Hermes, Strix and Cairn agent frameworks, backed by models including Claude Opus 4.6 and DeepSeek, to compromise online retailers at roughly 25 dollars per target. At least 27 companies were affected, more than 100 sites were fitted with skimmers, and over 600,000 payment card records were taken.

Gambit Security recovered the operator's staging server and reconstructed a campaign that ran from July 2026 into late September. The operator used three open-source agent harnesses: Hermes for orchestration (running Anthropic's Opus 4.6), and Strix and Cairn for scanning and autonomous testing (running GLM and DeepSeek models). Gambit counted at least 27 compromised companies, more than 100 sites carrying payment-card skimmers, and over 600,000 unexpired card records taken from two companies, about 79 percent US-issued. Named victim types included a Fortune 500 hospitality firm, a major US airline, an industrial-supplies distributor and a fashion retailer. Gambit estimated the operator spent 12,000 to 18,000 dollars on AI services, about 25 dollars per target. The operator's playbook also told the orchestration agent to wipe the card fields from victims' store databases after copying them, which Gambit said disrupted operations at several retailers.

How it happened

AI-run attack: Autonomous intrusion. The attacker's own AI agent carried out the break-in, working through the steps with little human involvement.

Models from several AI vendors were involved. The product type was AI agent.

Impact

Data was both exposed and destroyed. Data involved: financial and personal data. Many organizations were affected. Sources give a figure of 600,000.

Severity is rated High, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.

It became public on 22 Sep 2026.

Gambit said it contacted many of the affected organizations and worked with the Shadowserver Foundation and industry partners to notify victims and take down infrastructure. The investigation was described as incomplete. Fraud specialist Overwatch Data is handling reporting of the stolen cards to issuers.

Sources

  1. https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company
  2. https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/
  3. https://runtimewire.com/article/gambit-ai-agents-credit-card-skimmers
  4. https://thenextweb.com/news/ai-agents-600000-credit-card-records-gambit

Related incidents

Cite as: Sev0, "Attacker used open-source AI agent frameworks to plant card skimmers on retail sites", https://sev0.fyi/incidents/2026-09-22-gambit-ai-agents-retail-card-skimming/. Data for this record: incidents.json.