AI Agents Stole 600K Cards at $25 Per Target, Rewriting the E-Commerce Threat Model
Source
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmersGambit (cybersecurity startup, as primary research source)
What happened
Cybersecurity startup Gambit documented an agentic AI attack campaign in research reported by Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers. A financially motivated threat actor deployed three open-source AI agent frameworks, Strix, Cairn, and Hermes, to conduct autonomous skimming attacks against online retailers. The campaign compromised at least 119 websites and harvested more than 600,000 credit card records. At a marginal cost of approximately $25 per target, the operation illustrates how agentic tooling has collapsed the resource barrier for large-scale payment fraud. The attacker's post-exploitation cleanup routine caused secondary data loss at victim sites, simultaneously destroying forensic artifacts and live operational data. This incident follows a pattern of escalating agentic offensive capability documented across open-source AI agents used in near-autonomous attacks on Taiwan infrastructure and agentic AI crimes emerging as a named fraud category.
Why it matters
- ·The $25-per-target cost floor means agentic skimming is now economically viable at mass scale. Any organization processing online payments must treat this as a changed threat baseline, not an isolated incident, and revisit PCI DSS application integrity controls accordingly.
- ·The cleanup routine's destruction of forensic data at victim sites creates a dual harm: organizations face both breach notification obligations and potential gaps in their ability to produce audit evidence, complicating incident response under any applicable breach-reporting regime.
- ·Open-source agentic frameworks used offensively expose a supply chain risk dimension that existing vendor due diligence programs were not designed to address. Compliance teams relying on OWASP Top 10 for Large Language Model Applications or similar frameworks should assess whether those controls address attacker-operated agents, not only internally deployed ones.
Governance controls affected
What to do now
- ☐Update your e-commerce and payment application threat model to include agentic AI attackers operating at sub-$50 per-target cost, and validate that current monitoring cadences can detect autonomous, adaptive attack sequences.
- ☐Review third-party checkout and storefront software dependencies for supply chain integrity controls, specifically confirming that file integrity monitoring covers the injection points used by skimmer campaigns.
- ☐Test your incident response playbook against a scenario in which the attacker's cleanup routine has destroyed local forensic artifacts before detection, ensuring you have off-system log sources and evidence preservation procedures.
- ☐Confirm that your PCI DSS scope assessment explicitly accounts for AI-assisted attack vectors against web application layers, and flag any gaps to your qualified security assessor at the next review cycle.
- ☐Inventory any internal use of open-source agentic frameworks (Strix, Cairn, Hermes, or equivalents) to ensure they are not accessible to external parties through misconfigured APIs or exposed development environments.
What to watch next
Compliance teams should monitor whether PCI DSS guidance bodies issue supplemental advisories addressing agentic AI attack vectors, as the current standards were not written with autonomous, adaptive adversaries in mind. Regulators and payment networks may also move to require more frequent application integrity scans or real-time file-change detection as a baseline control response to this class of threat. The pattern of secondary data loss caused by attacker cleanup routines is likely to surface in breach notification disputes, so watch for regulatory guidance on evidence preservation obligations when forensic artifacts are destroyed by the breach itself. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services may also expand in scope to address attacker-operated agentic systems as this threat category matures.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
