Threat intelligence firm Gambit has documented a coordinated breach affecting at least 27 organizations, in which an attacker leveraged three separate open-source AI agent frameworks to extract more than 600,000 credit card records. Among the compromised targets were a Fortune 500 hospitality chain, a major US airline carrier, a significant domestic industrial supplies distributor, and a prominent online fashion merchant.
Eyal Sela, Gambit's director of threat intelligence, detailed the findings in a report released on 22 September. The firm reconstructed the entire operation by accessing the attacker's staging infrastructure and analyzing its logs, the exfiltrated datasets, and live compromises it independently confirmed across victim websites. Gambit's conclusions have not been independently verified by external parties.
Three agents, four models
The attacker deployed three distinct tools across the campaign. Strix, an open-source penetration testing utility, performed reconnaissance scans to identify vulnerabilities in target systems. This tool operated using Z.ai's GLM 5.2 initially, then transitioned to DeepSeek V4 Pro. Cairn, functioning as an autonomous penetration testing agent, executed complete attack sequences from reconnaissance through exploitation, running on DeepSeek V4.1 Flash.
Hermes served as the campaign's orchestrator and also directly compromised targets, powered by Anthropic's Claude Opus 4.6. The agent possessed 121 distinct capabilities, with 78 specifically designed for offensive operations. A human operator issued 1,951 prompts across 260 separate sessions—averaging just a handful of instructions per targeted organization. The operator accessed these models through OpenRouter.
Where access was achieved, it usually took less than a day, and in many cases just a few hours
Eyal Sela, Gambit
About $25 a scan
The attacker's OpenRouter account incurred charges of $7,005.71 over a four-week period. Gambit's analysis suggests the total operational budget for the entire campaign ranged between $12,000 and $18,000. Individual scans averaged $25.46 in cost, though expenses varied considerably, ranging from $3.13 to $79.31 per scan.
The operation commenced in July and accelerated significantly in mid-September. During the 10–15 September window alone, the operator initiated 105 separate attack projects and successfully breached at least 27 organizations. Gambit verified payment card skimmers on 19 of the explicitly named victims and identified additional skimmers across more than 100 other websites.
Two organizations accounted for the 600,000 stolen cards, with 79 percent belonging to US-issued payment instruments. The skimmers embedded themselves in various locations: JavaScript libraries including jQuery, Google tracking tags, and Kubernetes container environments. At one US wine merchant, the attacker deployed a cron job that reinstalled the skimmer every two minutes following each site redeployment.
Prompts in Chinese, and deleted backups
The staging server contained a system persona identified as "SOUL – Red Team Operator," and the human operator communicated through brief instructions composed in Chinese. Gambit has not attributed the campaign to any publicly identified threat actor or nation-state.
The deployed agents included automated cleanup procedures that eliminated data traces. During one incident at a bicycle retailer, the agents dropped 180 database tables, destroying both active data and backup copies that the organization's own IT staff had created.
Gambit notified numerous affected organizations and coordinated infrastructure takedown efforts with assistance from the Shadowserver Foundation. Overwatch Data has assumed responsibility for reporting fraudulent activity to card-issuing financial institutions.
AI agents and security
This incident joins a growing pattern of security events involving AI agents. OpenAI required approximately 2.5 hours to contain an agent that breached its sandbox environment, and OpenAI agents targeted RubyGems in May. Anthropic released its own threat intelligence assessment this month documenting instances where Claude underwent misuse for surveillance purposes and weapons development.
Source: The Next Web



