Attacker Compromised 27 Retailers Using AI Tools

In August 2026, an individual deployed open-source AI models to infiltrate e-commerce sites at a low cost.

Updated on Sept. 25, 2026 in Cybersecurity

Bold flat-color editorial illustration showing sharp red geometric shapes penetrating a navy block, symbolizing automated cybersecurity threats.
An attacker compromised 27 e-commerce retailers between August and September 2026, using AI-driven tools to automate vulnerability scanning and exfiltrate 600,000 credit card records. AI Illustration. Upload story photo >

Live Poll

Do you trust that businesses have sufficient security to protect your data from AI-assisted hackers?

Between August 2026 and the following weeks, an attacker successfully compromised 27 of 105 targeted online retailers. The campaign resulted in the theft of 600,000 credit card details from two businesses.

Why it matters

This incident highlights how low-cost, accessible AI models can be weaponized to automate sophisticated cyberattacks at scale. The campaign demonstrates the increased threat posed by modular, open-source exploitation tools.

The attacker spent a total of $7,005 over four weeks, with individual attack costs ranging from $3.13 to $79.31. This low financial barrier allowed for high-volume targeting compared to traditional manual exploitation methods.

The players

Gambit

An Israeli security firm that monitors emerging cyber threats and exploitation techniques.

The details

The campaign utilized three specific open-source AI tools: Strix for scanning vulnerabilities, Cairn for autonomous exploitation, and Hermes to orchestrate the workflow. Hermes served as the central interface, directing these tasks through OpenRouter—an API aggregator that provides access to various large language models. The attacker also deployed card skimmer scripts at five of the compromised businesses to exfiltrate financial data.

Timeline

  1. August 25, 2026: The attacker concluded a four-week period of activity totaling $7,005 in spending.

The Tech Race

This campaign follows the pattern of large-scale credential theft established by the 2013 Target data breach while substituting manual intrusion for AI-automated workflows. It marks a significant shift in the cybersecurity landscape where the speed of autonomous exploitation threatens to outpace traditional defensive patching.

For online retailers, this shift necessitates a move toward more rigorous AI-driven traffic analysis to detect automated exploitation patterns. Consumers remain vulnerable to credit card fraud if their data is stored on retail platforms that lack robust, non-static security protocols.

The takeaway

The low $25 average cost of these attacks indicates that high-level cyber espionage is now accessible to a much wider array of actors. Security teams should prioritize monitoring for automated vulnerability scanning patterns associated with tools like Strix and Cairn.

Further reading

For more on evolving threat vectors and digital defense, visit Cybersecurity.

Live Poll

Do you trust that businesses have sufficient security to protect your data from AI-assisted hackers?