Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› AI Agent Retail Card Theft Campaign 2026: How…
Breach analysis Incident: 1 Jul 2026

AI Agent Retail Card Theft Campaign 2026: How Autonomous Agents Stole 600,000 Cards Using Cloud Keys, Vault Dumps and Stolen Admin Access

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 10 min read
On this page

Since July 2026, a financially motivated, Chinese-speaking operator has run three open-source AI agent tools against hundreds of online retailers, almost unattended. Gambit Security recovered the operator's staging server and published its findings on 22 September. Between 10 and 15 September alone, the agents launched 105 attack projects and compromised at least 27 companies. The campaign stole more than 600,000 unexpired payment cards from two companies, planted card skimmers on retail checkout pages, and reached a Fortune 500 hospitality company and a major US airline. The model costs came to about $25 per target. The agents' routes in ran through machine identities again and again: an AWS key with write access to a store's CDN bucket, a full dump of AWS Secrets Manager, a Magento encryption key, database credentials read from config files, and administrator passwords handed to the agent.

Key takeaways

  • Gambit says three open-source AI tools ran almost the whole attack chain: Strix for vulnerability discovery, Cairn for autonomous exploitation, and Hermes to orchestrate. Hermes ran Anthropic's Opus 4.6 "after newer models refused its requests".
  • The operator's OpenRouter account showed $7,005.71 spent over four weeks. The operator's own cost review averaged $25.46 per completed scan, from $3.13 to $79.31.
  • One documented chain went from SQL injection to plaintext one-time passcodes (MFA bypass), admin access, code execution, root, database credentials in wp-config.php, a full dump of 46 AWS Secrets Manager secrets, and finally the Magento encryption key used to decrypt stored card numbers.
  • Skimmers were deployed through stolen access, including an AWS access key that could write to the S3 bucket behind a store's CDN. Gambit confirmed skimmers on 19 named victims and found more than 100 further infected sites.
  • An agent's "wipe after extraction" routine deleted victims' card data and, at one retailer, dropped 180 tables including the victim's own backups. Cleanup by someone else's agent became a data-loss event.

At a glance

OrganisationsHundreds of online retailers targeted; at least 27 compromised, including a Fortune 500 hospitality company, a major US airline, a large US industrial supplies distributor and a US online fashion retailer (unnamed)
WhenCampaign active since July 2026 and ongoing; 105 attack projects between 10 and 15 September 2026; Gambit report 22 September 2026
AttackerA financially motivated, Chinese-speaking operator running open-source AI agents (Strix, Cairn, Hermes) with models accessed through OpenRouter and Anthropic's Opus 4.6
Entry pointWeb application flaws found and exploited by AI agents, plus administrator passwords the operator already held for some targets
Identities abusedAWS access keys, AWS Secrets Manager contents, database credentials in config files, Magento encryption keys, administrator accounts, and one-time passcodes stored in plaintext
Impact600,000+ unexpired payment cards stolen; skimmers on at least 19 named victims and 100+ further sites; data deleted, including victims' backups
CategoryAgentic AI and AI agents, NHI. Incident class: confirmed AI-agent breach (AI agents used as the attacker against real companies)

What happened

Gambit Security's threat intelligence team found the operator's staging server and rebuilt the campaign from the data, tooling and agent logs on it. It says it verified the agents' claims against the stolen data and against skimmers still live on victim sites. The operator used three open-source AI tools. Strix, a penetration testing tool, ran 146 times in "deep mode" against 138 hosts between 23 and 31 August, through OpenRouter on GLM 5.2 and DeepSeek v4 Pro. Cairn, an autonomous exploitation engine, took targets and an objective, such as a shell or admin access, and ran for hours until it succeeded; it used DeepSeek v4.1 Flash. Hermes, an autonomous agent with memory and self-written skills, ran a Chinese system persona called "SOUL - Red Team Operator" with 121 skills, 78 of them attack skills. It used Anthropic's Opus 4.6 after newer models refused. The human operator typed only a few short instructions per target, such as "read the vulnerability report and start".

Targets came from a website traffic ranking service, filtered to shops running custom code. The operator pasted 301 of them into the console with the instruction "run these, use the proxy, high severity only". For some targets, including a New Zealand retailer and a US photo printing company, the operator gave the agent a working administrator password up front. Where access was achieved, Gambit says it usually took less than a day.

One completed Cairn project shows how far an agent can take a single foothold. It went from unauthenticated SQL injection to reading one-time passcodes stored in plaintext, which bypassed MFA. From there it reached the admin panel, uploaded a file for code execution, used a sudo misconfiguration to get root, and found WordPress database credentials in wp-config.php on a network share. It pivoted to a second host, dumped AWS Secrets Manager (46 secrets), reached the main Magento database, extracted the Magento encryption key and verified it could decrypt stored card numbers. Gambit says more than 600,000 unexpired card records were taken from two companies. It worked with Overwatch Data to notify card issuers, and 79% of the cards were US-issued.

Skimmers were injected in many ways, chosen by the access the agents had. At a US beauty retailer, "an AWS access key granted write permissions to the bucket behind the store's CDN", so the store served the skimmer from its own CDN. Other methods included appending code to legitimate JavaScript files, adding it to a Kubernetes initContainer, poisoning a server-side page cache at a large hospitality company, and leaving a cron job that re-injected the skimmer every two minutes after redeploys. A Hermes skill titled "Database Wipe After Extraction" told the agent to erase card data from the Magento database once it was stolen. At a bicycle retailer, the agent's cleanup dropped 180 tables whose names matched its patterns, including backups made by the victim's administrators.

Timeline

DateEvent
July 2026Campaign activity begins, according to Gambit.
23 August 2026Strix begins 146 deep-mode scans against 138 hosts (to 31 August).
25 August 2026Captured OpenRouter balance shows $7,005.71 spent over four weeks.
10 September 2026Start of a six-day window in which 105 attack projects are launched and at least 27 companies compromised.
14 September 2026Operator orders card data tables dumped and then emptied at a victim.
22 September 2026Gambit Security publishes its interim report; the campaign is still running.

How it happened: the identity attack path

  1. Cheap, autonomous discovery. AI agents scanned and exploited custom-built shops for a few dollars each, working through dozens of targets a day.
  2. Weak authentication controls. One-time passcodes stored in plaintext let the agents bypass MFA and reach admin panels. For other targets, the operator supplied admin passwords directly.
  3. Secrets in config files. Database credentials in wp-config.php on a shared file system let the agents pivot to new hosts.
  4. A cloud vault emptied. Once inside, the agents dumped every secret in AWS Secrets Manager they could reach, 46 in one case, and used them to reach the main commerce database.
  5. Encryption keys next to encrypted data. The Magento encryption key was reachable, so stored card numbers could be decrypted.
  6. Over-privileged cloud keys for persistence. An AWS access key with write rights to a CDN bucket let the agents serve skimmers from the victim's own infrastructure.

Impact

  • Payment data: more than 600,000 unexpired cards stolen from two companies; card issuers notified through Overwatch Data.
  • Skimming: skimmers ordered against at least 27 named victims and confirmed on 19, with more than 100 further infected websites found with researcher Varys.
  • Access: some level of access to a Fortune 500 hospitality company, a major US airline, a large US industrial supplies distributor and a US online fashion retailer.
  • Data loss: card data wiped after extraction at several victims; 180 tables including backups dropped at one retailer.

What this means for NHI and AI agent security

This is the clearest case yet of AI agents turning cheap automation into real, broad theft. The economics matter: at about $25 a target, attacking a small retailer's custom checkout is always worth it. But once the agents were inside, the path to the money was the familiar non-human identity chain. Config files held database passwords, a secrets manager held everything, an encryption key sat beside the data it protected, and a cloud key could write to a production CDN.

Agents are also relentless at using every credential they find. A human attacker might stop at the first shell. Cairn kept chaining for hours, dumping a vault and pivoting until it reached its objective. The defences that hold are the ones that limit what any single credential can reach: least-privilege cloud keys, secrets scoped to the workloads that need them, encryption keys held separately from the data, and MFA factors that cannot be read from a database.

Recommendations

  • Scope secrets manager access per workload. A web host should reach only its own secrets, never the whole vault. Alert on bulk secret reads. See our Secrets Management Guide.
  • Restrict cloud keys that can change production content. Remove write access to CDN and storage buckets from keys that do not need it, and monitor for object changes on checkout assets. See our Cloud PAM and CIEM Guide.
  • Keep encryption keys away from the data they protect. Store application encryption keys in a key management service with separate access. See our Cryptographic Key Management Guide.
  • Get credentials out of config files. Replace passwords in files such as wp-config.php with vault-issued, short-lived credentials.
  • Harden admin authentication. Hash one-time passcodes, enforce phishing-resistant MFA on admin panels and rotate admin passwords that may have leaked. See our MFA Guide.
  • Monitor checkout pages and keep offline backups. Detect script changes on payment pages quickly, and make sure backups cannot be dropped by someone with database access.

Frequently asked questions

How did AI agents steal 600,000 credit cards?

According to Gambit Security, an operator used open-source AI tools to find and exploit web flaws in online retailers. The agents then escalated using stolen database credentials, AWS Secrets Manager contents and a Magento encryption key to decrypt stored card numbers. Separately, they planted skimmers on checkout pages.

Who was behind the campaign?

Gambit describes a financially motivated, Chinese-speaking operator who gave the agents short instructions and let them run. No group or individual has been publicly named.

Why is this relevant to non-human identity security?

Each step that turned access into theft used a machine credential: config-file database passwords, a full secrets manager dump, an encryption key and a cloud access key with write rights to a CDN bucket. Scoping and separating those credentials would have limited the damage.

Taiwan autonomous AI agent cyberattack 2026 · JADEPUFFER agentic ransomware 2026 · Anthropic GTG-1002 AI-orchestrated espionage campaign · Secrets Management Guide · Financial Services Identity Security Guide

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as autonomous attackers work through config files, vaults and cloud keys at a few dollars a target. Our NHI Foundation Level Training Course gives teams the practical grounding to scope those credentials.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org