It was found that a campaign used a self-directed AI (artificial intelligence) agent to steal credit card information exceeding 600,000 cards and distribute payment skimmers to at least 119 websites. Cybersecurity researchers who tracked the campaign warned about the real-world realization of “low-cost, high-efficiency” AI hacking.
Key content
Valid credit card information for 600,000 cards or more was leaked from two companies, of which 488,372 were cards belonging to U.S. customers.
The researchers directly confirmed the skimmers at 19 victim sites that were disclosed with real names, and also linked more than 100 additional infected sites to the same campaign.
The total operation cost is estimated at around $12,000–$18,000, with an average of about $25 per target.
Hacking led by AI agents
According to the security firm Gambit Security, this operation automated all aspects of the attack, including target scanning, vulnerability exploitation, and post-intrusion activity management, using three open-source AI frameworks: Strix, Cairn, and Hermes. The campaign began in July and lasted at least until September 22. Investigators believe the operator suspected to be based in China gave the agents only basic instructions, which then carried out much of the work autonomously.
According to the researchers, the attackers stole large volumes of valid payment card data from two companies, including 488,372 U.S. consumer cards. In separate analysis, Gambit said skimmer installation commands were sent targeting at least 27 explicitly identified victim organizations, and actual infections were confirmed in 19 of them.
With help from another security researcher, Gambit additionally found more than 100 extra websites containing skimmer code used in the same campaign. BleepingComputer, a security outlet, ultimately counted at least 119 infected websites, which is a figure based on the number of infected sites—not the number of separate companies.
The affected organizations are said to include a Fortune 500 global hospitality group, a major U.S. airline, industrial supplies distributors, and online fashion retailers. The attackers hid the skimmers in JavaScript files, payment (checkout) pages, cloud storage, databases, Kubernetes environments, and more, and they also designed them to automatically restore even after malicious code was deleted using cron jobs.
One of the Hermes framework’s “skills” included instructions to the system: “After extracting and downloading all card data, erase the original fields after splitting them multiple times.” Gambit explained that, because of this “clean-up” process, data loss and work stoppages occurred at some retailers.
Related article: Ethereum could gain new growth momentum from AI payments demand – BlackRock
Cost structure of AI-based attacks
Gambit estimated the cost of this entire campaign at $12,000–$18,000. Based on that figure, the cost per target is only about $25. Similar numbers were also found in the operator’s own review notes: among 101 completed scans, the average cost was $25.46, and for individual targets it ranged from as low as $3.13 to as high as $79.31.
Researchers point out that the combination of automation and low operating costs creates an environment where even attackers without advanced technical skills can easily carry out large-scale campaigns. In fact, some cases were analyzed as having seen penetration within only a few hours after entering just one or two lines of short text instructions, followed by autonomous execution.
This campaign shows that agent-type AI beyond the level of a “helper” can independently orchestrate the entire attack process—from scanning to exploiting vulnerabilities, establishing persistence, and stealing data. Activity patterns tracked from July to September 22 suggest that this operation evolved beyond a one-off experiment into a sustained campaign, and the repeated emphasis on low cost per target also makes it economically feasible for repeat attacks.
Next reading: Claude captures a hidden CRISPR-like system in viral DNA
