[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvTH094ZYrNLV0nVo6Ll6zojpElOVWogsBOsFF7Mn6dg":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"e467383d-b150-43a5-8aea-91f5db07f2b2","AI-Powered Campaign Targets Hundreds of Online Retailers","ai-powered-campaign-targets-hundreds-of-online-retailers-f074e0","A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration. The post AI-Powered Campaign Targets Hundreds of Online Retailers appeared first on SecurityWeek.","A financially motivated, Chinese-speaking threat actor is leveraging three AI agents for an ongoing campaign against online retailers. The campaign, active since July, uses AI for vulnerability research, exploitation, and attack orchestration, leading to the compromise of at least 27 companies and the theft of over 600,000 credit card records. The attackers also injected skimmer scripts into multiple online stores.","AI-powered campaign targets hundreds of online retailers, stealing credit card data.","A threat actor is using autonomous AI agents in an ongoing campaign targeting hundreds of online retailers, cybersecurity outfit Gambit reports. Active since July, the campaign relies on three AI harnesses to automate the attack chain, including vulnerability research, exploitation, and orchestration. “Between 10 and 15 September alone, 105 attack projects were launched, and at least 27 companies were compromised to varying degrees,” Gambit says. The hackers stole information from over 600,000 unexpired credit cards from two of the compromised companies and injected skimmer scripts into five online stores. Additionally, they gained some access to a Fortune 500 hospitality company and to three US firms, including an airline, a private industrial supplies distributor, and an online fashion retailer. “The campaign goes back further, and has impacted at least tens of other companies since July 2026. Where access was achieved, it usually took less than a day, and in many cases just a few hours,” Gambit notes.Advertisement. Scroll to continue reading. Open source AI tools for automation Mounted by a Chinese-speaking, financially motivated threat actor, the campaign used the open source AI penetration testing tool Strix for vulnerability hunting. Between August 23 and 31, the attackers ran it 146 times in ‘deep mode’ against 138 hosts, through OpenRouter on GLM 5.2 and on DeepSeek v4 Pro. The generated reports were then handed to the autonomous penetration testing engine Cairn, which was used to launch 105 attack projects between September 10 and 15 on DeepSeek v4.1 Flash. Gambit retrieved 48 of the attack reports, as the others were deleted. “Each attack path was chosen by the harness in real time through extensive probing and exploitation attempts, resulting in dynamic and mostly different TTPs across victims,” Gambit notes. For the third stage of the attack, the threat actor used the open source autonomous AI agent Hermes, which has persistent memory, self-written skills, a searchable session archive, and a web console, and supports scheduled jobs. The adversary loaded a Chinese system persona and 121 skills, including 78 attack skills. Using Anthropic’s opus-4.6, Hermes handled orchestration, intrusions, tactical guidance, and direct hacking activities. Gambit identified “1,951 prompts typed by the human across 260 sessions – only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.” 600,000 credit cards stolen at marginal cost The threat actor used a website traffic ranking service to select targets, focusing on shops running custom code. A human operator pasted 301 results into the console, but also handpicked at least two targets for which they already had an administrator password. According to Gambit, at least 600,000 credit card records were stolen from two victim companies, including over 488,000 cards from the US. The cybersecurity firm also identified a Hermes agent skill designed to delete the stolen card data from the victim’s Magento database. Additionally, the agent deleted a bicycle retailer’s backup tables after being instructed to erase staging tables created within the database. As part of the campaign, the threat actor also focused on injecting skimmer scripts into online shops’ checkout pages. Gambit initially confirmed 19 victims. Working with security researcher Varys, it discovered over 100 additional infected websites. The skimmer was typically appended to a JavaScript file present on the website, but the threat actors also deployed it as a script tag, inside the site’s Google tag block, in an AWS S3 bucket, in database content fields, in a Kubernetes initContainer, and in the cached page model of the checkout page. “At a US wine retailer, the application redeploy restored the clean checkout bundle, so the operator left a cron job in the JBoss log directory that checked the file size every two minutes and appended the skimmer again whenever it was reverted,” Gambit notes. What matters most about the campaign, the cybersecurity firm notes, is that the operator incurred marginal cost through the use of open source tooling. Based on the retrieved data, Gambit estimates a mean cost of $25.46 over 101 completed scans. “This is a very concerning incident which demonstrates what the future of cyberattacks will more commonly look like. When the major AI players announced their agents had carried out breaches in testing scenarios, this caused serious concern, but given that these activities were not deliberately malicious, the incidents were contained,” Talion Cyber Security threat intelligence analyst Daniel Wilcock said. “Here we are seeing something very different. AI was deliberately used to maliciously target organizations under the pretense of running a pen test. This wasn’t social engineering; it was a full-scale attack, where agents were prompted to probe for weaknesses, which they did persistently, and wipe clean any evidence of the assault,” Wilcock added. Related: Astrana Health Data Breach Impacts Private, Confidential Information Related: Hackers Return $263 Million Stolen From Liquid Network Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted Related: Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Adobe Patches Critical Flaws in Connect, AEM FormsChrome 154 Patches 108 VulnerabilitiesArista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayCheck Point Patches Exploited Management Server Zero-DayBigCommerce Data Stolen via Ribon Apps HackRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of Downloads Latest News Island Raises $400 Million at $6.4 Billion ValuationOT Security Guidance: NIST Drafts Updated Guide, CISA\u002FFBI Advise on ICS IntegratorsBegin at the End: How to Enable Agentic RemediationSolarWinds Patches Critical RCE Flaws in Observability Self-HostedAstrana Health Data Breach Impacts Private, Confidential InformationUS Court Sentences Armenian Man to Prison for Ryuk Ransomware AttacksCritical WordPress Vulnerability Exploited Immediately After DisclosureIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU Decoder Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sam","https:\u002F\u002Fwww.securityweek.com\u002Fai-powered-campaign-targets-hundreds-of-online-retailers\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F05\u002Fdark-web-marketplace-credit-card.jpeg","2026-09-24T12:48:14+00:00","2026-09-24T14:00:12.379799+00:00",9,[18,21,24,26,28,31],{"name":19,"type":20},"Chinese-speaking threat actor","threat_actor",{"name":22,"type":23},"Strix","product",{"name":25,"type":23},"Cairn",{"name":27,"type":23},"Hermes",{"name":29,"type":30},"AI agents","technology",{"name":32,"type":30},"OpenRouter","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":33,"icon":35,"name":36,"slug":37},null,"Nation-state","nation-state",[39,44,46,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":58,"value":59,"context":60},"malware","skimmer scripts","Injected into online stores' checkout pages."]