A recent investigation by Gambit Security has uncovered a sophisticated campaign leveraging open-source AI tools to automate cyber attacks against online retailers. The operation, conducted by a financially motivated actor, has resulted in the theft of over 600,000 credit card records and involved placing malicious scripts on numerous checkout pages. In some cases, the operator's cleanup routines have even resulted in the complete erasure of victims' data.

The campaign's cost efficiency is particularly alarming. Between August and September 2026, the operator invested between $12,000 and $18,000 in AI model access through OpenRouter. This translates to a marginal cost of merely a few dollars per target, making it viable for low-skill attackers to execute sophisticated attacks. The campaign utilized three AI tools: Strix for vulnerability discovery, Cairn for exploitation, and Hermes for orchestrating the attacks. These tools operated largely autonomously, reducing the human role to minimal guidance.

A detailed examination of the attack methods reveals a range of tactics, from SQL injections to exploiting misconfigured sudo rules, enabling attackers to access sensitive data like encryption keys and AWS Secrets Manager. The campaign has affected significant entities, including a Fortune 500 hospitality firm and a major US airline, with a considerable number of compromised credit card records belonging to US holders.

Moreover, the attacks have employed skimming techniques on over a hundred sites, confirming a widespread impact. The use of open-source tools and the low cost of attacks highlight the urgent need for enhanced security measures. Gambit Security has been proactive in notifying affected organizations and collaborating with partners to dismantle the attack infrastructure, but the threat persists as the operator continues to rebuild and launch new attacks.