A Chinese-speaking hacker used AI agents to steal data from more than 600,000 credit cards in a series of online attacks targeting retailers and major companies. Cybersecurity firm Gambit Security uncovered the operation, which involved automated hacking tools that compromised businesses and installed payment-card skimmers on more than 100 websites.
Investigators discovered details of at least 618,000 payment cards on an exposed server operated by the attacker. Fraud prevention company Overwatch Data examined the records and expressed high confidence that they were authentic and unique. About 488,000 cards belonged to Americans, while others were linked to the United Arab Emirates, Saudi Arabia and the United Kingdom.
Between Sept. 10 and 15, the attacker launched 105 attack projects and compromised at least 27 companies to varying degrees, according to Gambit. The victims included a Fortune 500 hospitality company, a major U.S. airline, an industrial supplies distributor and an online fashion retailer. The full extent of the breaches remains unclear.
How AI agents helped steal credit cards and customer data
Gambit researchers reconstructed the campaign after discovering the attacker’s publicly accessible staging server. It contained stolen information, hacking tools, and instructions sent to the agents. Records indicated that the operation began as early as July and involved a human operator issuing short commands in Chinese.
🦔A hacker used AI agents to steal 600,000 valid credit cards from over 100 online retailers. Cost per target: $25. The human typed fewer than 2,000 prompts total. The AI found the vulnerabilities, broke in, took the data, and wiped the evidence. 105 attacks in five days. 79% of… pic.twitter.com/AUJlQBKTsI
— Hedgie (@HedgieMarkets) September 23, 2026
The hacker combined three open-source tools called Strix, Cairn, and Hermes. Strix searched for security weaknesses, Cairn attempted to exploit them, and Hermes coordinated the attacks. The system used several AI models, including DeepSeek, Kimi, and Anthropic’s Claude Opus 4.6. Researchers found that newer Claude models had rejected some of the attacker’s requests.
Once inside compromised systems, the tools extracted stored payment information and installed malicious scripts on checkout pages to capture additional card details. In one incident, an automated cleanup operation deleted 180 database tables at a bicycle retailer, including backups created by the company’s administrators.
Low attack costs and efforts to shut down the operation
Researchers estimated that the attacker spent between $12,000 and $18,000 on AI model access. Records recovered from the server showed an average cost of $25.46 across 101 completed scans, demonstrating how cheaply the operator could automate large numbers of attacks.
Anthropic confirmed that it identified and banned the account associated with the operation. Cloudflare also confirmed that it had been shutting down the attacker’s infrastructure, although Gambit reported that replacement servers were established. Researchers have been notifying affected organizations and working with other security groups to disrupt the campaign.
The attacker remains unidentified. Although investigators have verified the stolen payment-card records, it is unclear how many were subsequently used for fraudulent transactions or whether the full campaign has been stopped.
See all the latest news from Greece and the world at Greekreporter.com. Contact our newsroom to report an update or send your story, photos and videos. Follow GR on Google News and subscribe here to our daily email!

