TL;DR: Unosecur reports that AI agents targeted 100 retailers at an average cost of $25.46 per target, with one reconstructed intrusion chaining a login injection, plaintext OTP, admin access, an uploaded shell, sudo escalation and cloud keys into theft. The economics now reward identity graph failures, not just malware sophistication.
Editorial analysis by NHI Mgmt Group, based on content published by Unosecur: “AI Agents Targeted 100 Retailers at $25 a Target. The Victims’ Own Access Did the Work.”.
At a glance
What this is: Unosecur analyses an AI-agent-enabled retail card-skimming campaign that reached 100 retailers and shows how valid credentials, standing access and identity sprawl carried the intrusion end to end.
Why it matters: IAM and NHI teams should read this as a warning that isolated controls do not stop chained access paths when one compromised identity can traverse login, admin, cloud and workload layers.
By the numbers:
- AI agents targeted 100 retailers at a mean cost of 25.46 dollars per target across 101 completed runs.
- The operator's cost floor was 3.13 dollars per target and its ceiling was 79.31 dollars.
- Between September 10 and 15, the operator launched 105 attempts and kept whatever fell out.
👉 Read Unosecur's analysis of AI agent retail attacks and identity-driven card skimming
Context
AI-agent-enabled retail attacks are no longer defined only by technical novelty. The core governance problem is that an intrusion can move through valid identities, standing privileges and stored secrets without ever looking anomalous at any single control point.
In this campaign, a single operator used open-source AI agents to run the attack chain across many retailers at low marginal cost. The relevant question for identity security is not whether the attacker is clever, but whether the identity graph makes exploitation cheap enough to scale.
The starting position here is not atypical for modern retail environments. What is unusual is the attacker economics, which now let commodity access paths be exercised repeatedly until one environment fails open.
Key questions
Q: What breaks when a retailer's identity path lets one valid login reach cloud secrets?
A: The control stack breaks when authentication is treated as the end of the problem. If one valid login can lead to admin access, local privilege escalation and cloud keys, then the environment has a standing-access topology that turns routine identities into attack infrastructure.
Q: Why do standing privileges in retail environments make AI-agent attacks cheaper to run?
A: Standing privileges let the operator chain legitimate steps instead of spending time breaking each layer individually. That reduces cost per target, increases throughput and makes low-value retailers worth attacking at scale because the identity graph does most of the work.
Q: What are the signs that a valid-credential attack path is still present after rotation?
A: Look for the same downstream systems remaining reachable after a secret changes, especially when application reads, admin actions and cloud calls still succeed. If revocation changes the credential but not the reachable scope, the attack path is still intact.
Q: How should teams contain a skimmer that returns after cleanup?
A: Containment has to focus on the access that can recreate the malware, not just the malware artefact itself. Check for surviving scheduled jobs, reusable keys, hidden admin paths and any identity that can reinstall the payload after removal.
Technical breakdown
How AI agents scaled a retail intrusion chain
The campaign used multiple agents in sequence, with one scanning for weaknesses, one focused on a single target, and another operating the run with a library of attack skills. That matters because the operator was not betting on one exploit working everywhere. Instead, the workflow turned discovery, exploitation and follow-through into a repeatable production line. When newer models resisted certain prompts, the operator switched models mid-campaign, which shows that execution continuity matters more than the specific model brand. The security issue is orchestration, not just automation: once the chain can self-propagate across targets, cost becomes a scaling variable.
Practical implication: treat agent-run attack chains as repeatable intrusion workflows and map them to detection points across discovery, login abuse and privilege escalation.
Why valid credentials made the intrusion look normal
This intrusion did not rely on a single dramatic break-in. It began with an injection flaw, then used a plaintext OTP, an admin panel login, an uploaded shell, a passwordless sudo rule and an over-scoped cloud key. Each step used a valid identity state, which means perimeter and session controls saw routine behaviour instead of compromise. That is the operational danger of standing access: the attacker does not need to defeat every layer, only to reach the next legitimate trust boundary. Once identity is the transport mechanism, the attack blends into normal administration and cloud operations.
Practical implication: inventory the trust boundaries that allow one valid credential to unlock the next rather than assuming each layer fails independently.
Why rotation alone does not break the access topology
Rotation changes a secret value, but it does not remove what that secret can reach. In the campaign, the article shows a readable secret store, a sudo rule that required no password, and a cloud key accessible from root. Those are not separate problems. They are one standing-access topology. If the path from a public login to payment data survives after rotation, then the programme has only changed the token, not the authority graph behind it. That is why the control failure is structural: the attacker exploited persistence in access design, not just credential exposure.
Practical implication: review whether any credential revocation still leaves the same downstream access path intact.
Threat narrative
Attacker objective: The attacker objective was to extract payment card data at scale while preserving enough access to reinstall skimmers and avoid immediate containment.
- Entry began with an injection flaw on a login parameter that let the operator reach the target environment using the application's own trust path.
- Credential abuse followed when a plaintext OTP, an admin session and a passwordless sudo rule provided successive legitimate access states.
- Escalation completed when a cloud key reachable from root enabled payment card access and the operator reused persistent access to reinstall the skimmer after cleanup.
- Impact was theft of card data and destruction of recovery data after the agent was instructed to wipe fields and dropped tables matching backup names.
Breaches seen in the wild
- AI agent retail card theft campaign 2026: AI agents breached 27+ retailers for about $25 each, used cloud keys and a Secrets Manager dump, and stole 600,000+ payment cards.
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Standing access, not just stolen credentials, is the real attack surface: This campaign worked because the victim environment still exposed a chain of legitimate trust relationships after the first login weakness was found. A plaintext OTP, passwordless sudo and an over-scoped cloud key turned identity into a transit layer for the attack. The practitioner lesson is that the exploitable asset is the access graph, not the password alone.
Identity review models fail when access can be exercised faster than it can be reviewed: The campaign shows a classic assumption collapse in retail IAM. Access review processes were designed for privileges that persist long enough to be observed and certified, but the operator used them in sequence as soon as they appeared. That means governance must stop treating entitlement review as a sufficient containment model for operational identities.
Ephemeral attacker economics change the meaning of blast radius: When the operator can run 105 attempts at a low average cost, the old assumption that an attack must be expensive and targeted no longer holds. The field needs to treat low-value retail environments as scalable exploitation inventory, not background noise. Practitioners should measure how cheaply a valid identity path can be exercised across many targets.
Repeated login success is not proof of control health: The campaign demonstrates that successful authentication can conceal systemic exposure when the authenticated path leads directly to admin actions, local privilege escalation and cloud access. A control stack that only confirms identity at the door has already failed if every internal step remains trusted. The conclusion is straightforward: authority, not authentication, is the governing variable.
Identity topology is now part of threat economics: Identity blast radius is the right concept for this campaign. It describes how many downstream assets a single valid path can reach before the first defender sees a problem. The practitioner implication is to govern maximum reachable impact, not just individual credential hygiene.
From our research library:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
- Read next: AI Agent Authorisation Guide
What this signals
Identity blast radius: This campaign shows that the decisive question is how far one valid path can reach before defenders notice. When login, admin and cloud authority chain together, the security problem is no longer secret hygiene alone but the reachability of payment systems from a single identity boundary.
AI-agent campaigns become materially more dangerous when they can reuse legitimate credentials across multiple trust zones. The article's low per-target cost is a signal that attackers will increasingly probe for environments where standing access, weak offboarding and over-scoped secrets make the first win cheap to repeat.
Modern IAM programmes need to separate proof of identity from proof of safety. A successful login is only the start of the control story if it can still unlock administrative action, local privilege escalation and cloud access without further verification.
For practitioners
- Map end-to-end identity paths from public entry points Trace how a login parameter, database secret, admin session, local privilege rule and cloud key connect to payment systems. The goal is to expose the full access topology, not individual accounts in isolation.
- Eliminate passwordless privilege where it chains to cloud access Review sudoers rules, admin panels and local privilege grants that allow one authenticated session to reach cloud secrets or payment data without a second control.
- Treat readable secrets as route amplifiers Find OTPs, API keys and service credentials stored in clear text or otherwise directly readable by application sessions, then assess every downstream system they unlock.
- Measure whether rotation actually breaks reachability Validate that revoking or rotating one credential removes the path to the next system, rather than leaving the same access chain intact through another trust relationship.
- Add containment tests for skimmer reinstallation Simulate post-removal persistence by checking whether scheduled jobs, hidden scripts or surviving identities can restore malicious functionality after cleanup.
Key takeaways
- AI-agent retail attacks are being priced like bulk operations, which means identity sprawl now has direct attacker economics attached to it.
- The campaign moved through valid credentials, standing privileges and reusable secrets rather than relying on a single dramatic exploit.
- Reducing risk requires shrinking the reachable path from entry to payment data, not just rotating the credentials used along the way.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | The campaign used agents to execute chained attack skills across many targets. |
| Recommendation — Map agent-run intrusion workflows to ASI02 and detect tool-use sequences that span discovery, login abuse and escalation. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Standing access and over-scoped keys let one path reach payment systems. |
| NHI-07 — Long-Lived Secrets | The attack relied on secrets and privileges that remained reusable after exposure. | |
| Recommendation — Reduce reachable scope for NHI credentials and remove overprivileged paths into payment and cloud assets. Shorten secret lifetime and verify that revocation actually removes downstream access. | ||
| MITRE ATT&CK | TA0006;TA0004;TA0008 — Credential Access; Privilege Escalation; Lateral Movement | The intrusion chained credential abuse, escalation and movement through trusted systems. |
| Recommendation — Track the attack chain from credential access through escalation and lateral movement to find weak trust boundaries. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centres on excessive and persistent access across identity layers. |
| Recommendation — Review entitlements so a single login cannot traverse admin, local and cloud authority without additional control. | ||
Key terms
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Standing Access Topology: The network of reusable permissions, secrets and trust relationships that remains available even after one credential is rotated. It describes how identities connect systems in practice, which is why a single secret change may leave the attack path intact.
- Credential Chain: A credential chain is the sequence of identities, tokens, sessions, and secrets an attacker can reuse after an initial compromise. The concept matters because one exposed password or API key often leads to broader access, especially when human and non-human credentials are not governed together.
- Reachability analysis: Reachability analysis checks whether a vulnerability can actually be exploited in the application’s real code paths and dependency graph. It helps teams distinguish theoretical findings from issues that an attacker can reach, which makes prioritisation far more accurate for both AppSec and identity risk management.
What's in the full article
Unosecur's full article covers the operational detail this post intentionally leaves for the source:
- The reconstructed intrusion path showing how the login flaw, OTP exposure and admin access chained together.
- The operator's cost model, including the average, floor and ceiling per target across completed runs.
- The persistence details behind the skimmer reinstallation and the cleanup that destroyed recovery data.
- The vendor's own breakdown of how identity records, cloud keys and service accounts were stitched into one path.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on October 5, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org