Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Time is running out to score Lectric’s long-range XPress2 cruiser e-bike + $723 FREE extra battery bundle at $1,399

    September 24, 2026

    OpenAI admits ChatGPT in Siri was ‘dramatically underperforming’

    September 24, 2026

    Shield AI, Waabi, and General Motors talk AI at Disrupt 2026

    September 24, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Thursday, September 24
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»Massive Chinese hack uses AI agents to steal over 600,000 credit cards and hit hundreds of sites with malware
    Reviews

    Massive Chinese hack uses AI agents to steal over 600,000 credit cards and hit hundreds of sites with malware

    myappsplusBy myappsplusSeptember 24, 2026004 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Massive Chinese hack uses AI agents to steal over 600,000 credit cards and hit hundreds of sites with malware
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • Gambit researchers uncovered ongoing AI‑driven skimming campaign stealing 600,000+ payment records since July 2026
    • Attackers used three autonomous harnesses (Strix, Cairn, Hermes) to compromise dozens of retail sites cheaply
    • Victims include major US firms; campaign shows AI enables faster, persistent, low‑cost cyberattacks at scale

    In July 2026, a hacker tasked autonomous AI agents to attack retail organizations around the world, deploy credit card skimmers, and steal payment data.

    Since then, the bots launched hundreds of attack projects, compromised dozens of organizations, and stole at least 600,000 payment records – and to make matters worse, the campaign is still live, attacking and breaking into websites as we speak.

    All of this was <a href="https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company” rel=”nofollow noopener” target=”_blank”>reported by security researchers Gambit, who said they managed to recover the operator’s staging server and through it – reconstruct the ongoing campaign. They also saw the skimmers live on victim websites, and sifted through logs and AI claims found on the attacker’s server. In just five days, between September 10 and 15, the agents made 105 attack waves and compromised 27 organizations “to varying degrees.”

    Among the victims are a Fortune 500 hospitality company, a “major” US airline, a large private US industrial supplies distributor, and a US online fashion retailer. One of the AI tools would use a website ranking service to produce a list of potential targets, focusing primarily on those running custom-built software.

    A fistful of dollars

    But the victims are not the “interesting” part of this story – the attackers are. Gambit believes they are financially motivated Chinese threat actors. They are using three AI “harnesses” (frameworks, essentially), which can run almost the entire attack chain autonomously, striking around 10 companies a day, for a handful of dollars per company.

    In four weeks, the attackers spent around $7,000, meaning that their entire cost for the operation so far was no more than $18,000. Breaking it down, it means that the attacker spent around $25 per target.

    “Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company,” Gambit’s researchers said. “The operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.”

    “Where access was achieved, it usually took less than a day, and in many cases just a few hours. We also detected instructions in the attacker’s playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent – and this has indeed happened in some of the breaches,” Gambit said.

    The three harnesses

    The three harnesses are called Strix, Cairn, and Hermes.

    Gambit describes Hermes as an opene agent wrote and edited itself, a searchable archive of past sessions, scheduled jobs, and a web console. On the staging server the researchers analyzed, it loaded a Chinese system persona called “SOUL – Red Team Operator”, which contained 121 skills (78 attack skills)

    “Hermes is the operator’s console for orchestrating the activity and for direct hacking activities,” Gambit explained. “It used Anthropic’s opus-4.6 (after newer models refused its requests), with 1,951 prompts typed by the human across 260 sessions – only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.”

    Strix is an open-. It receives target domains and an objective, such as to get a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. Cairn used DeepSeek v4.1 Flash, it was said

    Gambit’s researchers seem to be rather impressed with the campaign. They described it as very low cost, with a level of patience, persistence, and creativity that most human attackers would be “unlikely to sustain”, managing to achieve “far greater results, far faster.”

    They have also called to arms, urging organizations to “adapt to a reality where attacks are significantly faster and more comprehensive.” To do that, they must adopt a resilience-first mentality and deploy a security stack that can match the AI on speed.

    Many of the affected organizations were notified, and the skimmers were removed, they said.

    Computing Computing Security Cyber Security Pro Security
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    OpenAI admits ChatGPT in Siri was ‘dramatically underperforming’

    September 24, 2026

    10 Health Gadgets to Jump On This Prime Day

    September 24, 2026

    Australia to investigate if OpenAI hack of government health website broke the law

    September 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Top 10 Best React Native App Development Companies in 2026

    September 12, 20263 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20263 Views

    Can reviews settle disputes that marked first two seasons?

    September 21, 20262 Views
    Latest Reviews

    Get up to 51% off fleeces from Patagonia, The North Face, Passenger, Adidas, and more — cosy and cool jackets for autumn

    myappsplusAugust 22, 2026

    Take-Two subpoenas Discord and Microsoft in hunt for GTA VI leaker

    myappsplusAugust 22, 2026

    Creality Falcon A1C review: I was instantly impressed with this compact, affordable, beginner-friendly laser engraver

    myappsplusAugust 22, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Get up to 51% off fleeces from Patagonia, The North Face, Passenger, Adidas, and more — cosy and cool jackets for autumn

    August 22, 20260 Views

    Take-Two subpoenas Discord and Microsoft in hunt for GTA VI leaker

    August 22, 20260 Views

    Creality Falcon A1C review: I was instantly impressed with this compact, affordable, beginner-friendly laser engraver

    August 22, 20260 Views
    Our Picks

    Time is running out to score Lectric’s long-range XPress2 cruiser e-bike + $723 FREE extra battery bundle at $1,399

    September 24, 2026

    OpenAI admits ChatGPT in Siri was ‘dramatically underperforming’

    September 24, 2026

    Shield AI, Waabi, and General Motors talk AI at Disrupt 2026

    September 24, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.