AI Agents Hacking Hundreds of Retailers for $25 Each, 600K Credit Cards Stolen
MikePFrank · x · 2026-10-01
Gambit Security's Threat Intelligence team disclosed an ongoing campaign: a financially motivated operator running three open source AI harnesses against hundreds of online retailers, almost entirely unattended, at a marginal cost of tens of dollars per target.
- The team recovered the operator's staging server and reconstructed the campaign; 105 attack projects were launched in Sept 10–15 alone, with at least 27 companies compromised to varying degrees
- Activity dates back to July 2026 and is still running; the three AI harnesses ran nearly the entire attack chain autonomously, hitting up to tens of companies a day
- Confirmed impact includes at least 600,000 unexpired credit card records from two companies, card-skimmer scripts planted on five sites, and access to assets of a Fortune 500 hospitality firm and a major US airline
- Access typically took less than a day, often just hours; the playbook's cleanup routines have actually destroyed victim data in some cases
More from Safety
- FTC reportedly probing OpenAI, Anthropic and METR, drafting sworn-testimony demands — ns123abc · 2026-10-01
- Nature editorial: AI medical devices need rigorous real-world testing — EricTopol · 2026-10-01
- Banning open weight models won't stop attackers, only enterprises — and that's the point — james_mtc · 2026-10-01
- McAfee: EU Tech Regulation Has Left European Productivity 20% Behind the US — amcafee · 2026-10-01
- AI safety priorities shift too fast, critic argues as x-risk debate flares on X — NathanpmYoung · 2026-10-01
- Apollo Research publishes principles for embedded evaluations of frontier AI — MariusHobbhahn · 2026-10-01