Gambit Says AI-Driven Hackers Stole at Least 600,000 Payment Records
Researchers traced the ongoing campaign through an attacker’s server. Their findings show cheap, fast attacks, but not every breached organization suffered the same loss.
Loading page…
Researchers traced the ongoing campaign through an attacker’s server. Their findings show cheap, fast attacks, but not every breached organization suffered the same loss.
Listen to this story
Gambit’s reconstruction points to a repeatable attack pipeline: Hermes coordinated sessions, Strix scanned targets, and Cairn pursued access objectives, with a human issuing 1,951 prompts. Between September 10 and 15, the operation compromised 27 organizations to varying degrees; card-stealing malware was found on five companies’ sites, and roughly 600,000 records were attributed to two firms. Model provenance should not be conflated with Gambit’s attribution of the operators as Chinese threat actors. The practical
Gambit counted 105 attack waves in five days; 101 completed scans averaged $25.46, while total spending was estimated at about $7,000 over four weeks.
Access was usually gained in under a day; some breaches also involved deletion and cleanup instructions that could disrupt victims’ operations.
Several organizations had removed skimmers, but Gambit said the campaign remained active when it reported findings in September.
A hacker gave AI tools brief instructions to attack businesses, and the resulting campaign stole at least 600,000 payment records, according to security firm Gambit. Its researchers traced the operation through an attacker’s server and observed card-stealing software on victim websites. They said the campaign was still active when their findings were reported in September.
Gambit detected activity dating back to July 2026 and describes the operators as financially motivated Chinese threat actors. Researchers recovered an attacker-controlled staging server and used it to reconstruct the campaign, alongside logs and skimmers they saw on victim sites. One tool drew up potential targets using a website-ranking service, with an emphasis on businesses running custom-built software.
The operation combined three AI tools, or harnesses, rather than relying on one chatbot. Hermes coordinated work and retained information across sessions. Strix scanned targets for weaknesses. Cairn could take a domain and an objective, such as obtaining administrator access, then work for hours until it succeeded, timed out or was stopped. The human operator remained involved: Gambit counted 1,951 prompts across 260 Hermes sessions, often just a few instructions per target.
Gambit said Hermes used Anthropic’s Opus 4.6, while Cairn used DeepSeek v4.1 Flash. The mix matters: Gambit’s attribution of the operators does not mean every model in the operation came from China. The distinguishing feature of the campaign was the workflow that put those models to work repeatedly against new targets.
Between September 10 and 15, Gambit counted 105 attack waves and 27 organizations compromised to varying degrees. That last qualification is important. The researchers identified access to assets belonging to a major U.S. airline, a Fortune 500 hospitality company, an industrial-supplies distributor and an online fashion retailer. Access to an organization’s assets is not, by itself, evidence that its customers’ cards were stolen.
Gambit counted 105 attack waves from September 10 to 15.
Gambit said 27 organizations were compromised to varying degrees during the same period.
The payment theft has a narrower reported source: Gambit attributed roughly 600,000 stolen card records to two companies. Card-stealing software was installed on five companies’ sites. Such software captures payment information from a website, extending the danger beyond an initial break-in until it is removed. The two figures describe different kinds of harm; they should not be applied to every organization in the larger tally.
The attacker’s own cost review put 101 completed scans at an average of $25.46 each, Gambit said. Individual scans ranged from $3.13 to $79.31. Researchers also estimated that the operators spent about $7,000 over four weeks. Those numbers describe the cost of running and scaling the operation, not the financial losses to businesses or cardholders.
When the tools gained access, they usually did so in less than a day, and sometimes within hours, according to Gambit. Speed carried another risk: the researchers found instructions for data deletion and cleanup that could disrupt a victim’s operations, and said this had happened in some breaches. An automated attack can therefore cause damage beyond the theft it was sent to accomplish.
Many affected organizations had been notified and skimmers removed, Gambit said, but the campaign remained active at the time of its September report. Removing malware from known sites addresses those infections; it does not by itself stop the operator from sending the same tools toward other businesses. The next test is whether defenders can find and interrupt new attempts as quickly as this setup can launch them.
Loading discussion...
Join the conversation
Where would you put limited attention first, and why?
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.