Decoding the world of cybersecurity

AI agents used in live retail attacks

Gambit Security says a financially motivated operator used three open-source AI harnesses to automate vulnerability discovery, exploitation, and campaign orchestration against online retailers.

AI agents used in live retail attacks
Summary
  • Gambit says 105 attack projects were launched between 10 and 15 September, with at least 27 companies compromised to varying degrees.
  • Researchers report recovering evidence of more than 600,000 unexpired payment-card records taken from two organisations.
  • The campaign used AI systems for scanning, exploitation, and orchestration while retaining a human operator directing the broader activity.

A financially motivated attacker used autonomous AI tooling across a live campaign against online retailers, according to Gambit Security research that provides unusually detailed evidence of agentic systems being used across multiple stages of real-world intrusion activity.

Gambit says it recovered the operator’s staging server and reconstructed activity involving three open-source AI harnesses: Strix for vulnerability research, Cairn for autonomous exploitation, and Hermes for campaign orchestration and direct attack activity.

Between 10 and 15 September, 105 attack projects were launched and at least 27 companies were compromised to varying degrees, according to the researchers. The wider campaign dates to July and remained active when Gambit published its interim findings.

Gambit also says it recovered evidence of more than 600,000 unexpired payment-card records taken from two victim companies and found card-skimming activity across compromised online shops.

The card dataset included records issued in the UK, Ireland, France, and numerous other countries, although issuing country does not establish where the breached company or individual cardholder was located at the time of compromise.

The evidential basis requires careful distinction. Gambit says its assessment draws on three sources: data and tooling recovered directly from attacker infrastructure, live compromises it verified independently, and logs or claims generated by the AI systems.

The researchers acknowledge that AI-generated claims can be inaccurate. Where direct verification was unavailable, they say they relied on the agent output in combination with technical evidence such as exploitation logs or listings of accessed assets.

That distinction is particularly important in research about autonomous attacks because agent-generated reporting can produce authoritative-sounding descriptions that do not necessarily prove what happened on the target.

The stronger finding here is that Gambit says it had access to the attacker’s infrastructure and independently confirmed substantial portions of the activity outside the agents’ own output.

The campaign also illustrates how roles traditionally performed manually can be separated across specialised systems. Strix conducted vulnerability research, Cairn pursued objectives such as obtaining shell or administrator access, and Hermes coordinated activity while receiving relatively short instructions from the human operator.

Gambit found 1,951 human prompts across 260 Hermes sessions. That does not make the operation fully autonomous: a person still selected or supplied targets, configured systems, issued instructions, and remained part of the campaign.

It does, however, suggest that one operator can delegate substantially more parallel technical work than could be performed manually.

The economics are also notable. Gambit says the attacker’s own cost review produced a mean model cost of $25.46 across 101 completed scans, ranging from $3.13 to $79.31 per target.

Those numbers represent AI-model usage rather than the total cost of criminal infrastructure or labour, but they illustrate how automation may lower the marginal cost of probing another organisation.

The operational consequences were not confined to deliberate theft. Gambit says a cleanup routine deleted data at one retailer after matching table names too broadly, affecting backup tables created by the victim’s administrators.

That introduces a resilience problem separate from the attacker’s intended objective. Autonomous offensive tooling can cause collateral operational damage through poorly scoped actions even when destruction is not the principal goal.

The research does not establish that autonomous AI has replaced human attackers. It indicates something more incremental but operationally important: one human can delegate portions of reconnaissance and exploitation to systems capable of running for hours across several targets.

That reduces the protection organisations gain simply from being too small or commercially uninteresting to justify sustained manual effort. When parts of discovery and exploitation can be automated cheaply, scalable opportunism becomes a more significant part of the exposure.

×