A financially driven individual has been operating three open-source AI tools against numerous online retailers, often without oversight This article explores gambit security staggering. . The results are alarming: over 600,000 credit card records have been stolen, scripts to gather card information have been placed on dozens of checkout pages, and in at least two cases, the operator’s cleanup routine completely obliterated the victims’ data.

AI Agents Credit Card Theft According to research published by Gambit Security, the activity, which began in July 2026 and continues to run, leveraged three off-the-shelf AI tools working in concert.

Strix handled autonomous vulnerability discovery, Cairn ran end-to-end exploitation for hours at a time until it achieved a shell or admin access, and Hermes orchestrated the entire campaign, launching intrusion jobs, steering activity, and providing tactical guidance during the impact stage. The Cairn attack campaign timeline (Image Source: Gambit Security) A staggering 600,000-plus card records were obtained from two victims, validated by anti-fraud firm Overwatch Data, revealing that roughly 488,000 cards, or 79 percent, belonged to US holders.

Injection methods varied by access level, including appending a loader to a legitimate jQuery file, poisoning an S3 bucket behind a CDN, and utilizing a Kubernetes initContainer or a cron job in a JBoss log directory that re-injected the skimmer every two minutes whenever a redeploy cleaned it.