Gambit researchers reportedly uncovered an ongoing AI-driven payment-skimming campaign that has stolen more than 600,000 payment records since July 2026. The attackers allegedly used three autonomous harnesses—Strix, Cairn and Hermes—to compromise retail sites at low cost.
Hi, this is a striking report, but the headline’s numbers and attribution should be treated as reported claims rather than confirmed facts until the original Gambit research is available for scrutiny.
What the report appears to show
The interesting development is not that AI somehow invented web skimming. The reported campaign appears to combine established attacks—finding vulnerable websites, gaining access, deploying malicious payment-page code and maintaining persistence—with agents that automate more of the repetitive work.
If accurate, the five-day figures quoted in the article suggest substantial operational scale. They do
not, by themselves, prove that every attack wave succeeded, that every claimed record was valid card data, or that AI operated without human supervision. Likewise, “compromised to varying degrees” could cover anything from limited access to a working skimmer; that distinction matters.
The phrase
“Chinese hack” also needs firmer evidence than infrastructure location, language settings or an assumed operator identity. Those are leads, not reliable attribution on their own.
What customers and site owners should do
For shoppers, there is no verified victim list in the supplied material, so there is no basis for assuming that every online purchase is exposed. Sensible precautions are:
- Monitor card transactions and enable instant purchase alerts.
- Report an unfamiliar charge through the card issuer’s official app, website or telephone number.
- If a merchant or issuer confirms exposure, follow the issuer’s replacement-card instructions.
- Prefer payment methods offering transaction tokens or virtual card numbers where available. These can limit the usefulness of stolen merchant-side payment data.
Retail-site operators should treat this as a conventional web-compromise problem with greater automation behind it: patch internet-facing applications and plugins, review administrative access, inspect payment-page changes, and investigate unexpected external scripts or outbound requests. Simply removing visible skimmer code is inadequate if the attacker’s original access remains active.
The claimed
$25 per target is catchy, but without the original methodology it is unclear what was counted—model usage alone, total infrastructure cost, successful compromises, or every attempted target. Cheap attempts and cheap successful intrusions are very different claims.