A financially motivated, Chinese-speaking threat actor has used autonomous AI agents in an ongoing campaign against hundreds of online retailers, cybersecurity company Gambit reports. Active since July 2026, the operation launched 105 attack projects between 10 and 15 September, compromising at least 27 companies to varying degrees. The victims included a Fortune 500 hospitality company, an airline, an industrial supplies distributor and an online fashion retailer.
More than 600,000 unexpired credit-card records were stolen from two organisations, including over 488,000 from the US, while skimmer scripts were injected into at least 19 sites initially identified by Gambit and more than 100 additional websites found with researcher Varys.
The attackers used three open-source AI tools: Strix for vulnerability research, Cairn for autonomous penetration testing and Hermes for orchestration and direct hacking. Strix was run 146 times in “deep mode” against 138 hosts between 23 and 31 August, while Cairn launched its 105 projects using generated reports. Gambit retrieved 48 attack reports and identified 1,951 human prompts across 260 sessions, with operators generally issuing short instructions in Chinese.
The skimmer was placed through several routes, including JavaScript files, Google Tag Manager content, AWS S3, database fields, Kubernetes and cached checkout pages. In one case, a cron job restored the skimmer after redeployment removed it. Gambit estimates 101 completed scans cost an average of $25.46, highlighting the low marginal cost of the campaign.