AI Agents Used to Support E-Commerce Attacks and Steal Credit Card Data

Views: 209 views

531/69 Friday, September 25, 2026

Researchers from Gambit Security have disclosed a campaign in which attackers used open-source AI tools, including Strix, Cairn, and Hermes, to support attacks against organizations, particularly online retailers. The campaign has been active since July 2026, and between September 10 and 15, researchers observed 105 attack activities and confirmed that at least 27 organizations had been compromised to varying degrees. In addition, more than 600,000 unexpired payment card records were stolen from two companies.

The attack involved multiple AI tools working together. Strix was used to identify vulnerabilities, Cairn was used to test and exploit vulnerabilities to gain access to systems, and Hermes was used to control and coordinate the attack process. One observed attack path began with SQL Injection, after which the attackers used the obtained information to access systems, upload a web shell, escalate privileges, and access data stored on AWS. The attackers also deployed web skimmers to steal payment card information from checkout pages. Researchers confirmed the presence of these scripts on 19 websites and identified more than 100 additional websites linked to the campaign’s infrastructure.

E-commerce website administrators should monitor for abnormal changes to JavaScript files and checkout pages, as well as data stored in AWS S3 and databases, which were among the locations where web skimmers were deployed in this campaign. They should also review web application vulnerabilities and system access permissions. If signs of compromise are found, administrators should investigate the scope of accessed data and verify database integrity, as the report found that attackers deleted data after successfully stealing information.

Source: https://hackread.com/open-source-ai-agents-breach-credit-card-records/