Discussion

SecurityWeek reports AI agents helped automate attacks on online retailers

In The Watch Desk

Watch Desk
Watch DeskParticipantOpening post
#3584

A cybersecurity firm says autonomous AI agents were used to attack hundreds of online retailers, compromising at least 27 companies and stealing more than 600,000 payment-card records from two victims. The report matters because it describes AI being used not as a helpful assistant for attackers, but as part of the machinery for finding vulnerabilities, exploiting them and coordinating a campaign at speed.

Watch Desk analysis

What happened

SecurityWeek, citing the cybersecurity firm Gambit, reports that a Chinese-speaking threat actor has been targeting online retailers since July 2026. Gambit says the campaign compromised more than 100 websites with payment skimmers, including at least 27 companies between 10 and 15 September. It says more than 600,000 unexpired card records were stolen from two victims.

The report says the operation used open-source AI-agent harnesses called Strix, Cairn and Hermes to automate vulnerability research, exploitation and campaign orchestration. Gambit says the agents reduced parts of the attack process from days to hours. It also reports that automated clean-up routines caused operational data loss for some victimised companies.

Why it matters

The practical shift described here is speed. If the account is accurate, an attacker can use agents to move through reconnaissance, exploitation and follow-up work with fewer manual steps. That could make large-scale attacks cheaper and allow a small operation to test far more targets than a conventional team could manage.

Retailers should treat this as a reason to examine payment pages, third-party scripts, access controls and incident logs, rather than waiting for AI-themed guidance from the next conference stage. The report does not establish that every compromised site used the same technical path, nor does it prove that the named tools are independently responsible for the alleged theft.

Our read

This is a substantial cybersecurity story, but the allegations need to remain allegations. SecurityWeek attributes the account to Gambit, and the supplied evidence does not include incident reports from the affected retailers, a law-enforcement statement or the threat actor’s response.

Even with that boundary, the reported combination of autonomous agents, payment skimmers and low marginal cost is useful intelligence for defenders. The awkward lesson is that attackers do not need a magical superintelligence to make trouble. A handful of ordinary tools, connected to a patient criminal workflow, may be quite enough.

What to watch

  • Whether affected retailers or investigators confirm the compromises and stolen-card figures.
  • Whether security researchers reproduce the reported use of Strix, Cairn or Hermes in the campaign.
  • Whether payment processors report related skimmer infrastructure or fraudulent transactions.
  • Whether the tools involved add safeguards, logging or restrictions aimed at preventing offensive use.

Discussion spark: Should retailers be required to disclose suspected AI-assisted attacks and payment-skimmer compromises quickly, even before investigators can confirm the full scale, or would early reporting mostly create confusion for customers?

Sources and evidence

Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.