Cyber & AI intelligence
Wasteland.
Briefs indexed2912
Issues30
Published Mondays07:30 CT
▣ Breach GAMBIT-AI-AGENT 2026-09-28

27 Companies Including a Major US Airline: AI Agent Campaign Steals 600,000+ Card Records

"A financially motivated operator ran three open-source AI agent harnesses (Strix, Cairn and Hermes) to break into at least 27 companies and take more than 600,000 unexpired payment card records, according to Gambit…"

A financially motivated operator ran three open-source AI agent harnesses (Strix, Cairn and Hermes) to break into at least 27 companies and take more than 600,000 unexpired payment card records, according to Gambit Security. In an interim report published on 22 September 2026, Gambit's director of threat intelligence, Eyal Sela, said the victims include a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor and a US online fashion retailer. Gambit rebuilt the campaign after it recovered the attacker's staging server. The operator's own cost review put the average completed scan at $25.46. The activity goes back to July 2026, and Gambit described it as still running at the time of disclosure. None of the named victims has made a public statement, and no regulator filing or CERT advisory has been published. Every figure below comes from Gambit's research as reported by the outlets and analysts cited. TNW notes that it has not independently verified the findings.

What Happened

Gambit says it reconstructed the operation from three kinds of evidence: material on the attacker's staging server (exfiltrated data and tooling), compromises it verified on live sites, and the operator's own logs. According to Gambit's report, The Register and Hackread, the operator launched 105 attack projects between 10 and 15 September alone and compromised at least 27 companies "to varying degrees." The agents worked through as many as "tens" of companies a day.

"Where access was achieved, it usually took less than a day, and in many cases just a few hours," Sela wrote.

The human operator had very little to do. Gambit counted 1,951 prompts across 260 sessions, which works out to a few prompts per target. Tech Times and Yahoo report that the prompts were short instructions written in Chinese. The Register describes the operator as Chinese-speaking. Gambit has not attributed the activity to any named group.

How far the campaign reached depends on which figure you use. Gambit's confirmed count is at least 27 companies in the six-day window from 10 to 15 September. Its report also says the operator targeted "hundreds of online retailers" and has affected "at least tens of other companies since July." Several secondary outlets (the Cloud Security Alliance, Tech Times and Yahoo Tech) use a figure of "100+" compromised sites or retailers. That number appears to come from Gambit's skimmer findings (see below), not from a confirmed count of breached companies. Read "27" as the confirmed minimum for one week and the larger figures as the wider footprint of the campaign.

What Was Taken

Why It Matters

Gambit and the CSA both present this as one of the most complete views so far of an autonomous AI attack pipeline, seen from the attacker's side instead of through victim forensics. Three things stand out for defenders:

  1. Very low cost. OpenRouter billing showed $7,005.71 spent in the four weeks to 25 August. The Register reports that the operator then kept going for three more weeks at roughly twice the daily volume of model calls. Gambit estimates the total at $12,000 to $18,000. A completed scan cost between $3.13 and $79.31, with a mean of $25.46 across 101 scans. At that price, attackers no longer need to be selective about targets.
  2. High speed with one operator. The CSA notes that 105 attack waves in a week from a single person is "a tempo and target count that would be very difficult for one person to achieve through manual exploitation." Most defenders set detection and response windows on the assumption of human-speed intrusions. Here, access usually came within hours.
  3. Damage nobody intended. Autonomous post-exploitation logic destroyed victim data. The CSA stresses that this collateral damage "need not have been deliberately intended or actively controlled by the operator." Incident responders should assume that an agent-driven intrusion may leave systems in an unpredictable state.

The tooling was freely available open-source software paired with commercial models bought through an API aggregator. Nothing about the stack was new or exclusive.

The Attack Technique

Gambit describes a three-layer pipeline:

The operator reached all of the models through OpenRouter. Yahoo News reports that the operator moved to OpenRouter after Anthropic banned the account originally tied to their model access. No other source in this set confirms that.

The sources describe the exploited weaknesses only in general terms. The CSA calls them "common web application flaws," and none of the sources name specific CVEs. Once inside, the agents stole stored card data where it existed and planted JavaScript skimmers on checkout pages to capture cards as customers entered them.

What Organizations Should Do

  1. Monitor checkout page integrity. Use Content Security Policy with reporting, Subresource Integrity, and script-change monitoring on payment pages to catch injected skimmers. PCI DSS 4.0 requirements 6.4.3 and 11.6.1 already require this for card-handling sites.
  2. Stop storing card data you don't need. Two companies accounted for the full 600,000 records. Tokenise payments or hand them to a hosted processor so that a web-app compromise does not expose a card database.
  3. Shorten detection windows. Intrusions here took hours. Alert on high-volume automated probing, unexpected admin or shell access, and new outbound connections from web servers, and set up response playbooks that can act within hours instead of days.
  4. Test yourself with the same tools. Strix and similar open-source agents are available to defenders too. Run them against your own external attack surface before an attacker does, and fix the common web application flaws they find first.
  5. Protect backups from web-tier compromise. Autonomous cleanup routines destroyed victim data. Keep backups immutable and segmented so that compromised application credentials cannot reach them.
  6. Hunt retroactively. Gambit says the campaign began in July and was still active in late September. E-commerce operators, particularly in retail, hospitality and travel, should review web logs and checkout scripts back to July 2026 for signs of compromise.

Sources: AI agents stole 600,000 credit cards for about $25 a target, Gambit... | Crook used three open source agents to break into a Fortune 500 hos... | Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Car... | AI Agents Are Hacking Online Retailers for $25 a Company | Autonomous AI Agents Breach 100+ Retailers: Security Implications | AI Agents Hacked 100 Online Retailers for $25 Each, Stealing 600,00... | Three Open-Source AI Agents Ran 27+ Breaches for $25 a Target. 600,... | AI Agents Stole 600,000 Payment-Card Records From 100-Plus Sites fo...