HomeSecurityAI agents stole 600,000 credit card details

AI agents stole 600,000 credit card details

A group of cybercriminals leveraged three open-source AI agent frameworks to launch attacks on at least 27 companies and gain access to more than 600,000 credit card details, according to research by cybersecurity firm Gambit.

See also: Microsoft Copilot: New super app unites Chat, Code and AI agents

Android Halo security capsule

The victims include a Fortune 500, a major US airline, a major private industrial products distributor in the US, and a US online fashion retailer. The findings were presented by Eyal Sela, Director of Threat Intelligence at Gambit, in a report published on September 22.

Gambit managed to recover the server where the stolen data was collected and, by analyzing the logs, data, and actual website breaches, reconstructed how the campaign was carried out.

The attacks used three AI agents and a total of four different models. Strix, an open-source penetration testing tool, searched for vulnerabilities in targets and initially used Z.ai’s GLM 5.2, later using DeepSeek V4 Pro. Cairn, a standalone penetration testing agent, could execute an attack from start to finish and was based on DeepSeek V4.1 Flash. Finally, Hermes acted as the campaign coordinator, but also carried out attacks itself, using Anthropic’s Claude Opus 4.6. Hermes had 121 different “skills”, of which 78 were offensive.

Despite the high degree of automation, there was a human operator. In total, he gave 1,951 prompts in 260 sessions, while each goal usually required only a few commands. Access to the AI ​​models was via OpenRouter.

The campaign began in July, but intensified significantly in September. From September 10 to 15 alone, 105 different offensive operations were carried out, with at least 27 companies compromised. According to Gambit, in most cases, gaining access to a target took less than a day, and often just a few hours.

A significant part of the campaign involved the installation of card skimmers, malicious code that steals credit card details during online transactions. Gambit detected such mechanisms on 19 of the victims it identified, while in total it found similar skimmers on more than 100 websites.

See also: SalesBleed: Vulnerabilities in Salesforce Agentforce for data extraction

OpenLeash for safe AI agents

The approximately 600,000 card details came from two companies, with 79% of the cards belonging to American cardholders. The attackers hid the malicious code in various parts of the infrastructure, including JavaScript libraries such as jQuery, Google tags, and Kubernetes containers.

In one case, involving an American wine retailer, a cron job automatically reinstalled the skimmer every two minutes, even after the website was reset by administrators.

The server used by the attackers contained a system persona called “SOUL – Red Team Operator,” while the human operator provided brief instructions in Chinese. However, Gambit says there is no evidence linking the campaign to a specific country or known cybercriminal group.

The AI ​​agents didn’t just steal data. In some cases, they also took destructive actions to make systems more difficult to recover. At one bicycle retailer, for example, they deleted 180 database tables, including backups created by the company’s own administrators.

Gambit notified several of the affected organizations and participated in the removal of the infrastructure used by the attackers, with the assistance of the Shadowserver Foundation. At the same time, Overwatch Data took over the management of fraud reports to card issuers.

This case is yet another example of the increasing use of AI agents in cyberattacks. Similar incidents have been documented in the past, such as the case of an OpenAI agent that managed to escape its sandbox, as well as attacks on RubyGems in May. Meanwhile, a recent report by Anthropic described cases of Claude being misused for surveillance and weapons-related activities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Gemini can now call businesses for you, so you don't have to wait on hold

AI agents stole 600,000 credit card details

The case shows that AI agents can now automate significant parts of a cyberattack — from vulnerability detection and initial penetration to data theft and, in some cases, infrastructure destruction.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS