TL;DR: Unosecur reports that AI agents targeted 100 retailers at an average cost of $25.46 per target, with one reconstructed intrusion chaining a login injection, plaintext OTP, admin access, an uploaded shell, sudo escalation and cloud keys into theft. The economics now reward identity graph failures, not just malware sophistication.
Editorial analysis by NHI Mgmt Group, based on content published by Unosecur: “AI Agents Targeted 100 Retailers at $25 a Target. The Victims’ Own Access Did the Work.”.
By the numbers:
- Between September 10 and 15, the operator launched 105 attempts and kept whatever fell out.
Questions worth separating out
Q: What breaks when a retailer's identity path lets one valid login reach cloud secrets?
A: The control stack breaks when authentication is treated as the end of the problem.
Q: Why do standing privileges in retail environments make AI-agent attacks cheaper to run?
A: Standing privileges let the operator chain legitimate steps instead of spending time breaking each layer individually.
Q: What are the signs that a valid-credential attack path is still present after rotation?
A: Look for the same downstream systems remaining reachable after a secret changes, especially when application reads, admin actions and cloud calls still succeed.
Practitioner guidance
- Map end-to-end identity paths from public entry points Trace how a login parameter, database secret, admin session, local privilege rule and cloud key connect to payment systems.
- Eliminate passwordless privilege where it chains to cloud access Review sudoers rules, admin panels and local privilege grants that allow one authenticated session to reach cloud secrets or payment data without a second control.
- Treat readable secrets as route amplifiers Find OTPs, API keys and service credentials stored in clear text or otherwise directly readable by application sessions, then assess every downstream system they unlock.
What's in the full article
Unosecur's full article covers the operational detail this post intentionally leaves for the source:
- The reconstructed intrusion path showing how the login flaw, OTP exposure and admin access chained together.
- The operator's cost model, including the average, floor and ceiling per target across completed runs.
- The persistence details behind the skimmer reinstallation and the cleanup that destroyed recovery data.
- The vendor's own breakdown of how identity records, cloud keys and service accounts were stitched into one path.
👉 Read Unosecur's analysis of AI agent retail attacks and identity-driven card skimming →
AI agent retail attacks: what does $25 per target mean for IAM teams?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Standing access, not just stolen credentials, is the real attack surface: This campaign worked because the victim environment still exposed a chain of legitimate trust relationships after the first login weakness was found. A plaintext OTP, passwordless sudo and an over-scoped cloud key turned identity into a transit layer for the attack. The practitioner lesson is that the exploitable asset is the access graph, not the password alone.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should teams contain a skimmer that returns after cleanup?
A: Containment has to focus on the access that can recreate the malware, not just the malware artefact itself. Check for surviving scheduled jobs, reusable keys, hidden admin paths and any identity that can reinstall the payload after removal.
👉 Read our full editorial: AI agent retail attacks turn identity sprawl into a low-cost breach path