A Hacker Used AI to Steal Data from More Than 600,000 Bank Cards

24.09.2026 5 minutes Author: Newsman

A Chinese-speaking hacker is using autonomous AI agents to launch large-scale attacks on online stores and has already stolen data from more than 600,000 active bank cards. According to Gambit Security, AI tools perform most of the work, while the average cost of attacking a single company is about $25.

The campaign has been active since at least July 2026 and has targeted hundreds of online retailers. According to Gambit Security’s research, the attacker launched 105 attacks in just five days, between September 10 and 15, with at least 27 companies compromised to varying degrees. Researchers identified targets including a Fortune 500 hospitality company, a major U.S. airline, an industrial goods distributor, and an online clothing retailer.

“More than 600,000 bank card records were stolen, and in one case the agent’s own cleanup procedure destroyed the victim’s data,” said Eyal Sela, Director of Threat Intelligence at Gambit Security.

At the time of discovery, all of the stolen cards were still active. Users in the United States were hit hardest, accounting for 488,372 cards, or 79% of the total. Other affected countries included the UAE with 13,559 cards, Saudi Arabia with 6,785, and the United Kingdom with 6,522.

Once access was obtained, the AI agents moved extremely quickly. In most cases, they needed less than a day to steal the data and complete the operation, and sometimes only a few hours. Researchers also found instructions on the attacker’s server ordering the agents to wipe bank card data from Magento databases after the theft. In one case, the cleanup process deleted 180 tables, including backup tables created by the company’s own administrators.

Three AI Tools Performed Almost All of the Work

The hacker used three main AI systems in the campaign: Strix, Cairn, and Hermes. Access to the models was provided through OpenRouter, a platform that offers access to a wide range of artificial intelligence models.

Strix, an open-source AI pentesting tool, was used to identify vulnerabilities. It initially ran with GLM 5.2 and was later switched to DeepSeek v4 Pro. Between August 23 and 31 alone, Strix was launched 146 times in deep-scan mode against 138 hosts.

Cairn was responsible for autonomously exploiting the vulnerabilities it found. It was given a domain and a specific objective, such as obtaining a shell or administrator access, after which the system could spend hours independently trying different attack paths until it succeeded or the allotted time expired. These attacks used the DeepSeek v4.1 Flash model.

Hermes served as the central coordinator of the campaign. It launched tasks, managed the other agents, helped determine the next steps, and was also used directly to carry out attacks. On the attacker’s server, Hermes was assigned a Chinese-language persona called “SOUL – Red Team Operator” and had access to 121 skills, 78 of which were related to offensive operations.

“Hermes is the operator console for coordinating activity and directly carrying out attacks,” the researchers explained.

For Hermes, the attacker used Anthropic Opus 4.6 after newer models began refusing to comply with his requests. Across 260 sessions, the human operator entered just 1,951 short prompts in Chinese, averaging only a few commands per target. Most of the work was performed by autonomous agents.

Зловмисник атакує 25 компаній одночасно.

One Attack Cost About $25

According to Gambit Security, the operator spent between $12,000 and $18,000 on OpenRouter tokens since July. However, because of the scale of the campaign, the cost of attacking a single company remained extremely low. The attacker’s own calculations showed an average cost of $25.46 across 101 completed scans. The cheapest target cost just $3.13, while the most expensive came to $79.31.

One of the campaign’s main objectives was to install web skimmers on checkout pages. These scripts silently intercept card details entered by customers during payment. Researchers identified more than 100 websites containing skimmers linked to the campaign.

The infection methods varied depending on the level of access the hacker obtained. Malicious code could be appended to legitimate JavaScript files, injected into Google Tag blocks, deployed through compromised AWS S3 resources, added to database content, or even embedded in Kubernetes environments. In one case, the attacker left behind a cron job that checked a file every two minutes and reinserted the skimmer whenever the store restored a clean version of the page.

AI Cuts Attacks From Weeks to Hours

Gambit Security highlighted not only the scale of the campaign but also its speed. Companies often need weeks to fix critical security issues, while autonomous AI agents can identify a vulnerability, breach a system, steal data, and cover their tracks within just a few hours.

“This campaign shows just how powerful attacks can be in 2026,” the researchers said.

Gambit notified the affected organizations and worked with partners to take down the attacker infrastructure it had identified. At the same time, researchers warned that because of the scale of the operation and the incomplete data available, the actual number of victims and the amount of stolen information could be even higher.

Conclusion

The campaign shows how autonomous AI tools can allow a single operator to attack dozens of companies at the same time with minimal human involvement and costs of only a few dozen dollars per target. For businesses, this means the time between the discovery of a weakness and the actual theft of data can shrink to just a few hours.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑