Hacker steals 600,000 credit cards while barely lifting a finger
They’re attacking hundreds of retailers with AI agents.

Hacker. Image by PeopleImages via Shutterstock.
- A Chinese-speaking attacker stole over 600,000 valid credit card records from online retailers.
- AI agents helped run dozens of attacks daily and often finished theft within hours.
- Researchers found skimmers on more than 100 websites, with US cardholders making up 79% of exposed cards.
- The attacker spent about $25 per target on AI model tokens, according to Gambit Security.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A Chinese-speaking attacker has stolen 600,000 credit card records from retailers, infected over 100 websites with card skimmers, and compromised several major companies. No human could sustain such a tempo – AI agents and tokens cost the hacker an average of $25 per target.
An ongoing cybercrime campaign is targeting hundreds of online retailers using a highly advanced AI setup. It consists of 3 harnesses and a 5-figure sum spent on tokens, as unveiled by Gambit Security’s Threat Intelligence team.
“More than 600,000 credit card records have been taken, and in one case, the agent's own cleanup routine destroyed the victim's data,” warns Eyal Sela, a Director of Threat Intelligence at Gambit.
All cards were still valid at the time, and the US was the most affected – 488,372, or 79% of affected credit cards belong to US customers.
Thousands of compromised credit card records belong to the United Arab Emirates (13,559), Saudi Arabia (6,785), the United Kingdom (6,522), and other countries.
The hacker instructs AI agents to wipe the credit card data from the victim’s Magento database once the theft is complete.
In just 5 days, between September 10th and 15th, the AI-run campaign launched 105 attacks and compromised 27 companies to varying degrees, according to Gambit's research. Among the victims are a Fortune 500 hospitality company, a major US airline, an industrial supplies distributor, and an online fashion retailer.
The operator has been active since at least July 2026, compromising dozens of companies more since then.
The recovered operator’s staging server unveils a staggering tempo: every day, AI bots attack “up to 10s of companies.” After the initial access, AI bots take less than a day, and in many cases, just a few hours to steal data and complete the cleanup.
Attacks cost $25 in average
The attacker relies heavily on 3 main AI tools and on access to several AI models on OpenRouter, a platform that provides access to hundreds of models.
The researchers estimate that the hacker has already spent between $12,000 and $18,000 on OpenRouter tokens since July. However, the figure is much more lucrative when spread across the number of companies attacked.
“The operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive,” Sela said.
The 3 deployed AI harnesses include the following:
- Strix, an open-source AI penetration testing tool, is used for vulnerability discovery. The hacker used GLM 5.2 and later DeepSeek v4 Pro on OpenRouter.
- Cairn, an autonomous penetration testing engine, was abused for end-to-end exploitation. It receives target domains and an objective, such as obtaining a shell or admin access, and then runs for hours until it achieves the goal. The attacker used DeepSeek v4.1 Flash.
- Hermes, an open-source autonomous AI agent, was used to orchestrate the campaign, launch intrusion jobs, steer the activity, and provide tactical guidance on impact and subsequent stages. The attacker used Anthropic’s Opus 4.6 after the newer models refused its requests.
The report noted that the operator prompted agents in Chinese. Hermes also used a Chinese persona named “SOUL – Red Team Operator.”
The AI agent had access to 121 skills, 78 of which were attack skills.
“Hermes is the operator’s console for orchestrating the activity and for direct hacking activities,” the researcher said.
The hacker barely moved a finger. Across 260 sessions, a human operator typed 1,951 short prompts – only a few prompts per target.
One of the operator's main objectives was to inject card-stealing skimmer scripts into the checkout pages of online shops. Over 100 websites were found infected with a skimmer associated with this campaign.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The report urges companies to adapt – remediation still often takes weeks, while attackers are done in hours.
“This campaign showcases just how powerful attacks can be in 2026,” the report concludes.
“Organizations planning against this should assume data loss can arrive as a side effect of someone else's cleanup routine. Once that is the assumption, resilience becomes the measure that matters: what can return, and how quickly,” the report concludes.
Gambit reached out to many of the affected organizations and took measures to take down the attacker’s infrastructure. Due to the scale of the operation and potentially incomplete data, the figures reported might be incomplete – researchers believe the campaign is likely larger than reported.