Gambit says an AI-assisted attacker stole 600,000 cards for about $25 per target Gambit Security reported that a financially motivated attacker used three AI agent tools — Strix for vulnerability scanning, Cairn for objective pursuit, and Hermes for coordination running Anthropic's Opus 4.6 through OpenRouter — to steal more than 600,000 valid card records and plant payment skimmers on at least 119 websites between July and at least September 22nd, spending an estimated $12,000 to $18,000 on AI services and related operations. Gambit's investigation, first reported by BleepingComputer, found 1,951 prompts across 260 Hermes sessions and 633 hours of Strix scanning across 146 runs against 138 hosts from August 23rd through August 31st, with 105 attack projects launched September 10th through September 15th and at least 27 companies compromised. Gambit describes the report as interim and cautions that agent records can be wrong, though it says researchers verified substantial parts against direct evidence. Gambit says an AI-assisted attacker stole 600,000 cards for about $25 per target Gambit says a human-directed campaign active since July stole more than 600,000 card records and placed skimmers on at least 119 sites. By RuntimeWire Staff https://runtimewire.com/author/runtimewire-staff · Published Primary source: BleepingComputer https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/ Why it matters The incident puts Gambit's recovery thesis against a documented attack in which agents both stole payment data and damaged database records. It also shows why security teams must measure how quickly critical systems can be restored, not only whether they have backups. Gambit Security https://gambit.security/?ref=runtimewire says a financially motivated attacker used three AI agent tools to break into online retailers, steal more than 600,000 valid card details and plant payment skimmers on at least 119 websites. The campaign was active from July through at least September 22nd, and Gambit estimates the attacker spent $12,000 to $18,000 on AI services and related operations. The report is a direct case study in the problem Gambit was built to address. Co-founder and CEO Alon Gromakov https://gambit.security/about-us?ref=runtimewire , along with co-founders Sa'ar Elias and May Kogan, founded Gambit after working in Israel's Unit 8200 and at cloud-security company Sentra. They saw organizations with security products, backups and disaster-recovery plans that still could not reliably establish which critical systems would recover, how quickly, or at what cost. Gambit's Balens platform https://gambit.security/?ref=runtimewire is designed to map infrastructure and validate those recovery paths. The account of the attack, first reported by BleepingComputer https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/?ref=runtimewire , comes from Gambit's investigation https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company?ref=runtimewire , which says its researchers accessed a staging server run by the attacker. Gambit describes the report as interim: some findings came from stolen data and tools recovered there, others from skimmers verified on websites, and some from logs and claims recorded by the agents. The company cautions that those agent records can be wrong, although it says researchers verified substantial parts of them against direct evidence. Three tools, one operator The attacker used Strix to scan for vulnerabilities, Cairn to pursue objectives such as administrator access or a shell, and Hermes to coordinate the work and direct follow-on activity. Gambit says Hermes used Anthropic's Opus 4.6 through OpenRouter https://runtimewire.com/models/fal/openrouter-router . Its recovered setup included 121 skills, 78 of them related to attacks, and a persona named "SOUL - Red Team Operator." The operation was heavily automated, but the evidence Gambit describes does not show an attack running without human direction. The operator supplied short instructions between agent sessions. Gambit found 1,951 prompts across 260 Hermes sessions, many of them brief requests to inspect a vulnerability report, test a route into an administrator panel or continue after gaining access. From August 23rd through August 31st, Strix ran 146 times against 138 hosts, totaling 633 hours of scanning time. Between September 10th and September 15th, the attacker launched 105 attack projects. Gambit says at least 27 companies were compromised to varying degrees during that period. BleepingComputer reported at least 119 websites with skimmers, while Gambit's report describes 19 confirmed skimmer installations among 27 named targets and more than 100 additional infected sites associated with the campaign. Gambit says the stolen card records came from two companies. It worked with fraud specialist Overwatch Data on the compromised cards; that analysis counted 488,372 cards issued in the United States, or 79% of the total. The victims were not identified publicly. Gambit described affected organizations as including a Fortune 500 hospitality company, a major US airline, a large industrial-supplies distributor and an online fashion retailer. The cost of a scan, and the cost of cleanup Gambit found an OpenRouter account showing $7,005.71 in spending over about four weeks as of August 25th. Based on later usage in the agent logs, it estimates the full bill at $12,000 to $18,000. The attacker's own cost review showed an average of $25.46 across 101 completed scans, with individual scans ranging from $3.13 to $79.31. Those are estimates from the evidence Gambit recovered, not an audited accounting of the entire operation. The price per target was small compared with the damage documented in the report. The agents inserted scripts into existing JavaScript files and checkout pages, and also modified database content, cloud storage, cached pages and Kubernetes deployments. At one retailer, a scheduled job restored a skimmer after the site's deployment replaced it. The variety of methods reflects the agent's ability to adapt its approach to the access and infrastructure it found, rather than relying on one reusable injection. The attacker's playbook also told Hermes to erase card data from Magento databases after exfiltration. Gambit found the instruction, "After extracting and downloading all card data, wipe the source fields in batches." Its report says this cleanup caused operational disruption at several retailers. In another incident described by Gambit, the agent's cleanup removed 180 tables matching broad name patterns, including tables administrators had created for backups. That is where Gambit's recovery focus meets the reported incident most directly. A retailer can remove a skimmer and still face a separate problem if the intrusion has altered payment records, backups or the infrastructure needed to restore service. Gambit's founding thesis centers on proving that recovery works as systems change; this campaign offers a concrete example of why a backup's existence alone does not answer what a business can restore after a breach. A security company reporting on its own thesis Gambit's findings are also a consequential piece of threat research from a company selling into the same broad problem it describes. Its founders emerged from stealth in February with $61 million in seed and Series A funding. Calcalist Tech https://www.calcalistech.com/ctechnews/article/r1gyp00n00wx?ref=runtimewire reported a $56 million round led by Kleiner Perkins https://www.kleinerperkins.com/?ref=runtimewire , with Spark Capital https://www.sparkcapital.com/?ref=runtimewire and Cyberstarts https://www.cyberstarts.com/?ref=runtimewire , following a $5 million seed round a year earlier. The company says Balens maps applications, dependencies, cloud resources and backups to assess recoverability. That commercial context does not settle whether every element of the campaign's scale is final. Gambit's published count combines direct evidence, live or previously observed compromises, and some agent logs; the company calls the investigation incomplete and says the true impact could be larger. The identities of the retailers and the eventual count of affected sites remain undisclosed in the report. What its evidence does establish is a costly new mismatch for defenders: a relatively inexpensive, AI-assisted operation can move through scanning, exploitation and persistence faster than many organizations can investigate and restore affected systems.