Gambit Security says the attacks were still running as of Sept. 22, after at least 27 companies were breached in six days and 600,000 payment card records were stolen from two.
An unidentified attacker used three AI tools to target hundreds of online retailers in a low-cost series of attacks that was still running when Gambit Security published its report on Sept. 22. Gambit said at least 27 companies were breached to varying degrees between Sept. 10 and 15 alone, with the campaign starting in July.
AI tools searched for weaknesses and broke into stores
The attacker used three AI-powered tools that could work with limited human direction. Strix searched websites for weaknesses, first using the GLM 5.2 model and later DeepSeek v4 Pro. Cairn used DeepSeek v4.1 Flash to try to break in. Hermes coordinated the attacks using Anthropic’s Opus 4.6 after newer models refused some of the attacker’s requests, Gambit said. The operator gave brief instructions, while the tools did much of the work.
To find targets, the operator fed Hermes a list of 301 shopping sites. The attacker filtered out stores using major retail software platforms, apparently favoring sites with custom-built systems that might be easier to break into.
Gambit said the hacker launched 105 attacks from Sept. 10 to 15. Where the tools gained access, they usually did so within a day and sometimes within hours. The attacker’s own figures put the average AI model cost of searching a company’s website for weaknesses at $25.46, based on 101 completed searches. That’s the cost of looking for a way in, regardless of whether the attacker succeeded.
Attacker stole credit card data, sometimes erased it, and kept checkout theft code in place
Gambit said the attacker stole more than 600,000 payment card records from two companies. Gambit found software on 19 shopping websites that could steal customers’ card details at checkout. Working with another researcher, Gambit identified more than 100 additional websites with code linked to the attacks.
Further, Hermes was instructed to erase card data from victims’ systems after stealing it. At a bicycle retailer, one of the attacker’s AI tools mistakenly deleted 180 database tables, including the retailer’s own backups, while clearing away its own files.
At a large U.S. hospitality company, the attacker planted card-stealing code in the checkout page. At a U.S. wine retailer, the attacker set up a task that checked every two minutes and restored the code whenever the retailer’s website update removed it.
Gambit says the attacker also got some level of access at a Fortune 500 hospitality company, a major US airline and an industrial supplies distributor.
The attacks reflect a disturbing trend of human-led, but AI-driven cyberattacks. Last week, Google reported a large credential-theft operation built and run in less than six hours that stole 23,800 credentials and digital access keys.
Gambit based its interim report on data recovered from the attacker’s server, evidence of affected websites, and attack logs. Some claims in those logs could not be independently confirmed. Gambit said it contacted affected organizations and worked with partners to take down the attacker’s infrastructure. The attacks were still running as of Sept. 22.

