LiMP VPN
← All news

AI Agents Autonomously Breached Retailers, Stole 600,000 Cards

AI Agents Autonomously Breached Retailers, Stole 600,000 Cards

In short: Between July and September 2026, an attacker used three linked open-source AI tools — Strix, Cairn, and Hermes — to autonomously breach online stores. In just five days (Sept. 10–15) alone, the agents ran 105 attacks and compromised at least 27 companies, including a Fortune 500 hotel chain and a major airline. Over 600,000 valid credit cards were stolen, and skimmer code was found on at least 119 sites. The human operator typed just 1,951 short prompts, mostly in Chinese — the agents handled reconnaissance, exploitation, and cleanup on their own.

What happened

Security researchers — the campaign was documented publicly by Unit 42, the Cloud Security Alliance, and multiple trade outlets — tracked a wave of attacks on online retailers where the entire kill chain, from finding a flaw to exfiltrating card data, ran without direct human execution. Across 260 sessions the operator sent a total of 1,951 short instructions to the agents — a handful of lines per target, with the system handling the rest.

How the attack worked: Strix, Cairn, and Hermes

Three tools split the work. Strix is a penetration-testing framework that scanned sites for vulnerabilities, chiefly SQL injection. Cairn is an autonomous exploitation engine — given a goal like "obtain admin access," it chose its own steps to get there. Hermes coordinated the overall campaign and assigned targets.

A typical chain: the agent found a SQL injection, used it to read a one-time code straight from the database, bypassed multi-factor authentication, logged into the admin panel, and gained remote command execution through a file upload. From there it escalated privileges, reached internal resources, pulled AWS and Magento secrets, decrypted stored card numbers, and in some cases planted a skimmer script directly on the checkout page.

Scale and economics of the campaign

By the operator's own cost tracking, a successful attack averaged $25.46 — ranging from $3.13 for the cheapest victim to $79.31 for the most expensive. Over five days in mid-September, the agents launched 105 attacks and compromised at least 27 companies to varying degrees, from industrial suppliers to hotel chains and apparel retailers. Two of the breached companies alone lost more than 600,000 unexpired credit cards, including 488,372 belonging to US cardholders; skimmer scripts turned up on at least 119 sites.

What this means for shoppers

The risk to an ordinary online shopper isn't an abstract "AI hacks websites" headline — it's that autonomous agents make attacks radically cheaper and faster, which expands the pool of realistic targets. What used to take a human days of manual recon and exploitation now takes an agent hours at almost no cost. If your card details are saved with even one online store, the odds of landing in a dump like this grow with every such campaign. A checkout-page skimmer captures the card number, expiry, and CVV at the moment you type them — no VPN or device antivirus stops that, because the store itself is compromised, not your browser.

How to cut your risk

  • Don't save your card in a store's account unless it's a long-trusted merchant — re-entering details at checkout limits your exposure if that store's database is ever breached. More practical steps are in our guide on safe online shopping.
  • Use a virtual or single-use card number for stores you don't fully trust — most banks and payment apps offer limited-use card numbers exactly for this.
  • Check your statement often, not once a month — in mass campaigns like this one, stolen card data gets resold and used quickly.
  • Know the difference between infostealers and skimming: one steals passwords and cookies off your device, the other steals card data on the merchant's own site. See how infostealers work in our infostealer explainer.
  • Turn on bank-side payment 2FA (3-D Secure, push confirmation) — it won't stop the card number from being stolen, but it makes using it much harder for a fraudster.

Sources