Redbot Labs / Threat Intelligence
AI Agents Compromise Online Retailers in Campaign Stealing 600,000+ Payment-Card Records
- Incident ID
- RBT-TI-0086
- Organization
- AI-Assisted Cybercrime / Payment-Card Theft / Web Skimming
- Reported Location
- United States — Country-Level Impact / Global Campaign
- Severity
- Critical
- Category
- AI-Assisted Cybercrime / Payment-Card Theft / Web Skimming
- Record Date
- 2026-09-22
Incident Summary
Gambit Security reported an AI-assisted criminal campaign targeting online retailers, with 105 attack projects launched during September 10–15 and at least 27 companies compromised to varying degrees.
Its investigation identified theft of more than 600,000 payment-card records, checkout skimmers, and destructive activity. These figures describe different aspects of the campaign and should not be treated as equivalent victim counts.
What Happened
Coordinated AI tooling
The operator used Hermes, Strix, and Cairn to coordinate activity, identify weaknesses, and pursue exploitation objectives.
Payment theft and persistence
Agents obtained access to commerce environments and deployed card-stealing scripts. Researchers also documented database theft and a cleanup operation that deleted 180 tables at one retailer.
Evidence and limitations
Gambit reconstructed events from recovered infrastructure, stolen data, verified compromises, and agent logs. Its interim report cautions that some agent-reported outcomes were not independently confirmed.
The incident details above come from Gambit’s primary investigation
Affected Systems
Online Storefronts / Checkout Scripts / Commerce Databases / Administrative Interfaces / Cloud Assets
Attack Vector
AI-Assisted Vulnerability Exploitation / Credential Abuse / Checkout Script Injection / Data Exfiltration
Business Impact
Payment-card exposure
Forbes reported approximately 618,000 card records on the attacker’s infrastructure. Overwatch Data assessed the records as likely legitimate and unique; approximately 488,000 were associated with Americans.
Broad commercial targeting
Reported targets included large enterprises and smaller retailers. The available reporting does not establish that every targeted organization suffered the same degree of compromise.
Unconfirmed financial losses
The reporting did not establish whether the stolen card details had been used successfully for fraudulent purchases. Anthropic told Forbes it identified and banned the account involved. Forbes investigation
Redbot Analysis
Validate the path to payment data.
Redbot recommends testing how an external application weakness could lead to administrative access, exposed credentials, cloud permissions, or sensitive databases. Assess those connections together so remediation addresses the full route to business impact.
Treat checkout changes as sensitive operations.
Review who can modify storefront scripts, tag-management settings, deployment artifacts, and content-delivery assets. Validate that unauthorized changes generate actionable alerts and that restored pages cannot be silently modified again through another access path.
Separate recovery permissions from production access.
A compromised application account should not be able to destroy both production information and its recovery copies. Test restoration using isolated backups and verify that recovered systems no longer contain the access paths that enabled the intrusion.
Exercise defenses against repeated attempts.
An assessment should examine whether controls withstand sustained probing and changes in technique. A blocked initial attempt is only one result; teams also need to understand whether another reachable application, identity, or integration provides access to the same sensitive resources.

