Skip to content
See the World Through ScienceA project of ALLATRA

AI Agents Broke Into Online Stores for About $25 a Target, Security Firm Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A person in a white shirt sits at a desk holding a payment card in both hands, with a computer keyboard in the foreground.
A shopper holds a payment card at a computer keyboard. Gambit Security says card-stealing code was planted on the checkout pages of online stores it studied (illustrative)."Online Shopping" by danielfoster437, via flickr, BY-NC-SA · BY-NC-SA

The security firm Gambit Security said in a report published Sept. 22 that a single financially motivated operator compromised at least 27 companies in under a week by pointing open-source AI agent tools at online retailers and leaving them to run almost unattended. Gambit says it recovered the operator's staging server and reconstructed the campaign from what was on it.

The firm says that at least 600,000 unexpired credit card records were taken from two of those companies, and that card-stealing scripts were planted on the checkout pages of others. It calls the report interim and says the real total is probably larger. Gambit's report puts the operator's own cost review at a mean of $25.46 for each completed scan of a target, a price at which the firm argues the economics of attacking a company no longer filters anyone out.

The firm describes the victims as mostly ordinary web shops, alongside larger organizations it does not name: a Fortune 500 hospitality company, a major U.S. airline, an industrial supplies distributor and an online fashion retailer. Overwatch Data, the fraud specialist Gambit worked with to notify card issuers, reported that 79% of the stolen cards were issued in the United States.

Gambit says that where the software got in, it usually took less than a day. Not all of the damage was theft. At one bicycle retailer, Gambit says, the software's cleanup step deleted 180 database tables, including backups the company's own administrators had made. Instructions to erase card data from a victim's database once it had been copied were written into the operator's own working notes.

Its account rests on data recovered from the server, on card-stealing scripts it confirmed were still live on victim sites, and in part on logs and claims produced by the software itself. The campaign goes back to July 2026 and is still running. Gambit says it has notified affected organizations with the Shadowserver Foundation and other partners and worked to take the infrastructure down.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

AI Agents Broke Into Online Stores for About $25 a Target, Security Firm Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.