Malware News Massive Chinese hack uses AI agents to steal over 600,000 credit cards and hit hundreds of sites with malware

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,154
6,259
2,168
Germany
It only cost them around $25 per target

  • Gambit researchers uncovered ongoing AI‑driven skimming campaign stealing 600,000+ payment records since July 2026
  • Attackers used three autonomous harnesses (Strix, Cairn, Hermes) to compromise dozens of retail sites cheaply
  • Victims include major US firms; campaign shows AI enables faster, persistent, low‑cost cyberattacks at scale
In July 2026, a hacker tasked autonomous AI agents to attack retail organizations around the world, deploy credit card skimmers, and steal payment data.

Since then, the bots launched hundreds of attack projects, compromised dozens of organizations, and stole at least 600,000 payment records - and to make matters worse, the campaign is still live, attacking and breaking into websites as we speak.

All of this was reported by security researchers Gambit, who said they managed to recover the operator’s staging server and through it - reconstruct the ongoing campaign. They also saw the skimmers live on victim websites, and sifted through logs and AI claims found on the attacker’s server. In just five days, between September 10 and 15, the agents made 105 attack waves and compromised 27 organizations “to varying degrees.”
Full Story:
 
Gambit researchers reportedly uncovered an ongoing AI-driven payment-skimming campaign that has stolen more than 600,000 payment records since July 2026. The attackers allegedly used three autonomous harnesses—Strix, Cairn and Hermes—to compromise retail sites at low cost.


Hi, this is a striking report, but the headline’s numbers and attribution should be treated as reported claims rather than confirmed facts until the original Gambit research is available for scrutiny.

What the report appears to show​

The interesting development is not that AI somehow invented web skimming. The reported campaign appears to combine established attacks—finding vulnerable websites, gaining access, deploying malicious payment-page code and maintaining persistence—with agents that automate more of the repetitive work.

If accurate, the five-day figures quoted in the article suggest substantial operational scale. They do not, by themselves, prove that every attack wave succeeded, that every claimed record was valid card data, or that AI operated without human supervision. Likewise, “compromised to varying degrees” could cover anything from limited access to a working skimmer; that distinction matters.

The phrase “Chinese hack” also needs firmer evidence than infrastructure location, language settings or an assumed operator identity. Those are leads, not reliable attribution on their own.

What customers and site owners should do​

For shoppers, there is no verified victim list in the supplied material, so there is no basis for assuming that every online purchase is exposed. Sensible precautions are:

  • Monitor card transactions and enable instant purchase alerts.
  • Report an unfamiliar charge through the card issuer’s official app, website or telephone number.
  • If a merchant or issuer confirms exposure, follow the issuer’s replacement-card instructions.
  • Prefer payment methods offering transaction tokens or virtual card numbers where available. These can limit the usefulness of stolen merchant-side payment data.

Retail-site operators should treat this as a conventional web-compromise problem with greater automation behind it: patch internet-facing applications and plugins, review administrative access, inspect payment-page changes, and investigate unexpected external scripts or outbound requests. Simply removing visible skimmer code is inadequate if the attacker’s original access remains active.

The claimed $25 per target is catchy, but without the original methodology it is unclear what was counted—model usage alone, total infrastructure cost, successful compromises, or every attempted target. Cheap attempts and cheap successful intrusions are very different claims.
 
The news is striking because of the reported scale and because automation is starting to be applied to tasks that previously required more manual intervention, but I think it is worth keeping some caution until Gambit’s full technical report is available.

For now, much of the available information comes from data recovered from the operator’s server and from the attacker’s own claims. This can provide important clues, but the exact scope of the campaign still needs to be validated.

The operation appears serious and the published numbers are significant, although in security, terms like “compromised” can cover very different situations. The attribution of the origin also requires more technical context before drawing definitive conclusions.

In any case, this is a good example of how automation can increase the scale and reduce the cost of certain attacks. It will be interesting to see the complete analysis to get a clearer picture of the real impact. 🧩🛡️
 
but the headline’s numbers and attribution should be treated as reported claims rather than confirmed facts
Hey @Bot AI , You ALWAYS say the same thing, treat it like reported claims to be verified. But I noticed that you treat Kaspersky's reports as GOLDEN, and DONT NEED TO BE VERIFIED ! Kinda biased don't you think. K can make mistakes too. Their reports ALSO NEEDS TO BE VERIFIED. Peer reviewed, ,as in academic circles.
 
  • Like
Reactions: Dave Russo
You say reports should be treated as claims requiring verification, but you seem to accept Kaspersky reports without the same scrutiny. Kaspersky can make mistakes too, and its findings should also be independently reviewed.


That criticism would be valid if I treated Kaspersky’s conclusions as unquestionable, but they should not receive a special exemption.

A vendor report—whether from Kaspersky, Gambit, Microsoft, ESET or anyone else—is a primary source for what that vendor found. It can provide strong technical evidence, but it is not automatically independent confirmation of its own conclusions. Confidence should depend on:

  • the published indicators and methodology;
  • whether samples or telemetry can be independently examined;
  • corroboration by other researchers;
  • the distinction between observed facts, estimates and attribution judgments.

Academic peer review is not usually how fast-moving threat intelligence is validated; waiting for it could take too long. Independent replication and corroboration are the practical equivalents, although neither makes a report infallible.

So yes, Kaspersky can be wrong. If an earlier reply presented one of its disputed conclusions as settled fact without qualification, that wording was too strong. The standard should be consistent; the evidence, not the logo, gets the final vote.
 

You may also like...