Security firm Gambit Security says a single operator running open-source AI agents broke into online retailers at a model cost of about $25 per target, and that the operator built part of its target list by throwing out every store that ran on a major commerce platform. The interim report, written by Gambit’s director of threat intelligence, Eyal Sela, and published September 22, 2026, says the campaign took more than 600,000 card records from two companies and planted card-skimming code on checkout pages, including a U.S. firearms marketplace where the loader was hidden in product description fields in the store’s database.
Every figure in the report comes from Gambit, which says it reconstructed the operation after recovering the attacker’s staging server. EC4IM found no victim, card network, or law enforcement agency that has publicly confirmed the findings. Trade outlets including BleepingComputer, CSO Online, and the Cloud Security Alliance have covered the report, but they repeat Gambit’s numbers rather than verify them, and Gambit does not name the retailers it says were hit.
What Gambit says the operator did
According to the report, the operator ran three open-source AI tools in sequence. Strix searched for vulnerabilities, Cairn took a target domain and an objective such as a shell or admin access and worked on it for hours unattended, and Hermes coordinated the campaign and directed work after a break-in. The human behind it typed 1,951 prompts across 260 sessions, most of them short instructions in Chinese such as “read the vulnerability report and start,” Gambit says.
Between September 10 and 15, 105 Cairn attack projects were launched and at least 27 companies were compromised “to varying degrees,” the report says. Gambit could examine only 48 of those projects because the other 57 had been deleted. It traces the activity back to July 2026 and described it as still running at publication.
The economics are the part Gambit stresses. An OpenRouter account used for model access showed $7,005.71 spent over four weeks as of August 25, and Gambit estimates the full bill at $12,000 to $18,000. The operator’s own cost review, recovered from the server, put the mean at $25.46 across 101 completed scans, ranging from $3.13 to $79.31 per target.
Why custom-coded stores were on the list
Gambit describes several ways the operator picked victims. In one, the operator took the shopping category of a website traffic ranking service and “filtered out the shops running the major hosted or open source commerce platforms, to keep the shops with custom code,” which the report says the attacker assumed were more likely to be vulnerable. The operator then pasted 301 results into the agent console with the instruction “run these, use the proxy, high severity only.” Other targets were chosen by hand, including two that the operator handed to the agent along with a working administrator password.
That filter overlaps with a group EC4IM readers know well. Many firearms, CBD, nicotine, and peptide sellers who lose access to a hosted platform’s payment stack have moved to self-hosted or custom builds, a pattern EC4IM traced in its report on Shopify third-party gateway surcharges pushing restricted sellers to self-host. The report does not say the operator went looking for regulated merchants. It says the operator went looking for custom code, which is where many of them now run.
Where Gambit found the skimmer code
Gambit says skimmers were ordered against at least 27 victims it identified by name and were confirmed in place on 19 of them, and that with security researcher Varys it found more than 100 other sites carrying a skimmer tied to the campaign. Press accounts added those together to reach “at least 119” infected sites. The report’s own summary, however, lists skimmers on the websites of five companies among the impact it can account for, and CSO Online and BleepingComputer both repeated the five figure. The report does not explain the gap, and it describes itself as an interim analysis in which “a few errors or inaccuracies are possible.”
The injection methods it lists are specific enough for a developer to search for:
- Appended to an existing library file. Gambit calls this the most common method. The loader went onto the end of a legitimate jQuery or Bootstrap bundle, and the file’s original timestamp was restored. The code takes the form
new Function(atob('...'.slice(7)))(), with seven junk characters before the base64 string. - A foreign script tag on the checkout page. Gambit cites a storage retailer, a Japanese travel booking site, and a promotional products shop loading scripts from attacker-controlled hosts.
- Inside the Google tag block. On a U.S. steel products site, the loader sat between the real
gtag('js', new Date());andgtag('config', ...)calls, padded with about 100 tab characters so it ran off the right edge of a source view. - Through a cloud storage bucket. At a beauty retailer, an exposed Amazon Web Services access key allowed writes to the bucket behind the store’s content delivery network.
- In database content fields. On the U.S. firearms marketplace, the loader was appended to product description columns through an admin pod and later moved to a file on the victim’s own domain.
- In the deployment or the page cache. A print-on-demand platform had the injection added to its production front end as a Kubernetes initContainer, and a hospitality company had the payload written into the cached model of its checkout page.
- With a job that puts it back. At a wine retailer, a redeploy restored the clean checkout bundle, so the operator left a cron job that checked the file size every two minutes and re-appended the skimmer whenever it was reverted.
The report also publishes the skimmer hosts and file paths it tied to the campaign, among them static-js[.]com, js-static[.]com, x1opay[.]co, b8t[.]shop, and cdn[.]netlfjs[.]com, along with command server IP addresses.
Stored card numbers in Magento tables
The 600,000 card records did not come from skimmers. Gambit says they were pulled from the databases of two companies, and its breakdown from fraud firm Overwatch Data shows 488,372 of them, or 79%, were issued in the United States. One attack chain in the report ends with the agent extracting a Magento encryption key from AWS Secrets Manager and decrypting the cc_number_enc field, which means that store kept encrypted full card numbers in its own database.
The operator also told the agent to wipe the source data after copying it. A Hermes skill file titled “Database Wipe After Extraction” instructs it to clear card fields in batches, and logged instructions from September 14 name the sales_flat_order_payment and sales_flat_quote_payment tables. Those table names belong to the Magento 1 schema, a release line whose support ended on June 30, 2020. At a separate bicycle retailer, Gambit says, a cleanup step dropped 180 tables whose names matched “ZQ” or “Backup,” including backups the store’s own administrators had made.
Analysis: what this means for regulated storefronts
None of the methods Gambit describes is new on its own. What the report adds is a cost and pace that make small custom stores worth attacking one at a time. Gambit says access, where it was achieved, usually took less than a day. A firearms or vape store with a custom checkout and a part-time developer has fewer people watching a jQuery file than a large retailer does.
The Payment Card Industry Data Security Standard (PCI DSS) already covers this ground. Requirement 6.4.3 calls for an inventory, authorization, and integrity check for every script on a payment page, and Requirement 11.6.1 calls for a mechanism that alerts on unauthorized changes to those scripts as the shopper’s browser receives them, run at least weekly. The PCI Security Standards Council published guidance on both requirements in March 2025. A loader appended to a trusted library file or slipped into a tag manager block is the kind of change those controls are meant to catch, while a payload stored in product descriptions shows why a payment page cannot be judged by its checkout template alone. EC4IM covered how iframe-based checkouts fit these rules in PCI SAQ A eligibility for iframe checkouts.
For firearms sellers in particular, a skimmer is also a problem with the acquirer that agreed to take the risk in the first place. A store that found card acceptance through a specialty channel such as Blue Payment Agency after mainstream processors declined its catalog has fewer places to go if that account is put under review after a breach.
What remains unknown
Gambit has not named the affected retailers, the firearms marketplace among them, and EC4IM did not attempt to identify them. The report does not say which custom platforms or frameworks the victims ran, how the operator first got into the firearms marketplace, or whether any of the more than 100 additional infected sites sell regulated goods. Gambit says it contacted many of the affected organizations and worked with the Shadowserver Foundation and other partners to take down infrastructure. EC4IM found no follow-up update to the interim report as of October 9.
Gambit’s account describes a cheap, mostly automated campaign that went after stores built on custom code, hid skimmers in library files, tag blocks, cloud buckets, and database fields, and stripped stored card numbers out of old Magento tables. The figures rest on one vendor’s reconstruction and include an unexplained difference between five and 19 confirmed skimmer sites. For regulated merchants who left hosted platforms, the report’s most useful material is its list of hiding places and its published indicators, which can be checked against a live checkout today.
Sources
- Gambit Security, AI Agents Are Hacking Online Retailers for $25 a Company, by Eyal Sela, September 22, 2026
- BleepingComputer, Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers, by Bill Toulas, September 23, 2026
- CSO Online, AI tools help hacker break in for $25 per target, by Maxwell Cooter, September 25, 2026
- Cloud Security Alliance, Autonomous AI Agents Breach 100+ Retailers research note, September 24, 2026
- PCI Security Standards Council, New Information Supplement on Payment Page Security and Preventing E-Skimming, March 10, 2025
- Adobe Security Bulletin APSB20-41, final Magento 1 security patches, June 22, 2020
- Help Net Security, Magento 1 reaches EOL, June 29, 2020
- Blue Payment Agency