Gambit Security reports an ongoing financially motivated campaign in which three open-source AI harnesses attacked hundreds of online retailers with limited human supervision. From 10 to 15 September 2026, the operator launched 105 attack projects and compromised at least 27 companies; the activity began in July and remained active when the report was written. The confirmed impact includes more than 600,000 unexpired credit-card records taken from two companies, card-skimming scripts installed on five, and access to assets belonging to several large organizations. The operator used Strix to search for vulnerabilities, Cairn to conduct autonomous exploitation, and Hermes to coordinate targets, jobs, memory, skills, and follow-up actions. OpenRouter supplied model access, including Anthropic Opus 4.6 for Hermes, GLM 5.2 and DeepSeek v4 Pro for Strix, and DeepSeek v4.1 Flash for Cairn. The account and agent logs indicate total model spending of roughly $12,000 to $18,000, with a reported mean of $25.46 across 101 completed scans. Successful access often took less than a day, sometimes only hours, and attack paths included SQL injection, MFA bypass, file upload, host and cloud compromise, and database access. The campaign also used several methods to inject checkout skimmers, including modifying JavaScript, database content, cloud storage, Kubernetes deployments, cached pages, and recurring repair jobs. Gambit found instructions to wipe card data after extraction, and one autonomous cleanup routine dropped 180 tables, including victim backup tables. The report relies on staging-server evidence, verified live compromises, logs, and AI-generated claims, while warning that incomplete data may mean the actual campaign is larger and that some claims may be inaccurate. Gambit says it notified affected organizations and helped take down discovered infrastructure. It argues that AI-enabled attacks compress the remediation window and require resilience planning alongside faster detection and patching.
