Skip to content
Menu
Menu

AI Tools Drive Low-Cost Attacks on Hundreds of Online Retailers

Gambit Security says the attacks were still running as of Sept. 22, after at least 27 companies were breached in six days and  600,000 payment card records were stolen from two.

 

An unidentified attacker used three AI tools to target hundreds of online retailers in a low-cost series of attacks that was still running when Gambit Security published its report on Sept. 22. Gambit said at least 27 companies were breached to varying degrees between Sept. 10 and 15 alone, with the campaign starting in July.

AI tools searched for weaknesses and broke into stores

The attacker used three AI-powered tools that could work with limited human direction. Strix searched websites for weaknesses, first using the GLM 5.2 model and later DeepSeek v4 Pro. Cairn used DeepSeek v4.1 Flash to try to break in. Hermes coordinated the attacks using Anthropic’s Opus 4.6 after newer models refused some of the attacker’s requests, Gambit said. The operator gave brief instructions, while the tools did much of the work.

To find targets, the operator fed Hermes a list of 301 shopping sites. The attacker filtered out stores using major retail software platforms, apparently favoring sites with custom-built systems that might be easier to break into.

Gambit said the hacker launched 105 attacks from Sept. 10 to 15. Where the tools gained access, they usually did so within a day and sometimes within hours. The attacker’s own figures put the average AI model cost of searching a company’s website for weaknesses at $25.46, based on 101 completed searches. That’s the cost of looking for a way in, regardless of whether the attacker succeeded.

Attacker stole credit card data, sometimes erased it, and kept checkout theft code in place

Gambit said the attacker stole more than 600,000 payment card records from two companies. Gambit found software on 19 shopping websites that could steal customers’ card details at checkout. Working with another researcher, Gambit identified more than 100 additional websites with code linked to the attacks.

Further, Hermes was instructed to erase card data from victims’ systems after stealing it. At a bicycle retailer, one of the attacker’s AI tools mistakenly deleted 180 database tables, including the retailer’s own backups, while clearing away its own files.

At a large U.S. hospitality company, the attacker planted card-stealing code in the checkout page. At a U.S. wine retailer, the attacker set up a task that checked every two minutes and restored the code whenever the retailer’s website update removed it.

Gambit says the attacker also got some level of access at a Fortune 500 hospitality company, a major US airline and an industrial supplies distributor. 

 

The attacks reflect a disturbing trend of human-led, but AI-driven cyberattacks. Last week, Google reported a large credential-theft operation built and run in less than six hours that stole 23,800 credentials and digital access keys.

Gambit based its interim report on data recovered from the attacker’s server, evidence of affected websites, and attack logs. Some claims in those logs could not be independently confirmed. Gambit said it contacted affected organizations and worked with partners to take down the attacker’s infrastructure. The attacks were still running as of Sept. 22.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!