AI Agent Card Skimming Now Costs Attackers $25 a Target
Autonomous AI agents have pushed the marginal cost of breaking into an online store down to roughly the price of a takeaway meal. A single financially motivated operator aimed three open-source frameworks at hundreds of retailers in an AI agent card skimming campaign that pulled more than 600,000 unexpired payment card records and planted card-stealing scripts on live checkout pages, according to an interim advisory from the security firm Gambit Security.
The activity has run since July and was still underway when Gambit published its findings on 22 September. The firm describes an operator who issued short instructions and let the harnesses handle discovery, exploitation and follow-on decisions with little supervision.
What the Advisory Documents
Between 10 and 15 September, the operator launched 105 distinct attack projects. At least 27 companies were compromised to varying degrees inside that six-day window. Gambit accounts for card-stealing scripts on the checkout pages of five stores and for at least 119 sites touched over the life of the campaign.
The arithmetic of that burst is worth pausing on. Roughly 17 attack projects went out each day, and about one in four produced some level of access, a strike rate that would be unremarkable for a human team and is notable only because almost nobody was driving it.
Two victims supplied most of the haul. Gambit recovered evidence of more than 600,000 valid, unexpired card records, including 488,372 belonging to U.S. customers. Victim categories named in the advisory include a Fortune 500 hospitality group, a major U.S. airline and an online fashion retailer. In one intrusion, the agent's own cleanup routine destroyed the victim's data backups.
| Framework | Role | Function |
|---|---|---|
| Strix | Scanning | Vulnerability discovery across retail targets |
| Cairn | Exploitation | Autonomous break-in against identified flaws |
| Hermes | Orchestration | Campaign management and tactical decisions |
The tooling is entirely off the shelf. Strix handled scanning and flaw detection, Cairn ran autonomous exploitation, and Hermes orchestrated the operation. The models driving them were commodity frontier systems, among them GLM 5.2, DeepSeek v4 Pro, DeepSeek v4.1 Flash and Anthropic's opus-4.6.
The victim list also undercuts a common assumption about who gets hit by automated retail attacks. A Fortune 500 hospitality group and a major U.S. airline are not under-resourced shops running outdated carts, yet both appear among the affected categories. Target size did not act as a shield.
The Economics Behind AI Agent Card Skimming
Gambit measured a mean cost to the attacker of roughly $25.46 across 101 completed scans, with individual jobs ranging from $3.13 to $79.31. Estimates of total campaign spend vary between accounts, from about $8,000 to $18,000. At that price, a failed attempt is overhead rather than a loss.
The two sides of the ledger do not resemble each other. An attacker spends tens of dollars per target. A breached retailer absorbs incident response, forensic review, customer notification and the reissuance of hundreds of thousands of cards. That asymmetry is why the campaign could run for three months without needing a high success rate.
The cost curve also changes who can launch such an operation. At $25 a target, the barrier sits within reach of one person working alone rather than a group with a budget, which is what Gambit's evidence points to here.
Timing matters as much as price. July through September is the run-up to peak retail traffic, when checkout pages change frequently and third-party scripts are added for promotions. That churn gives a skimmer a wider window to blend in before anyone audits the script chain.
Why Ordinary Bot Defences Are Shaped Wrong
Retail anti-automation tools are built to catch volume: thousands of requests from one address, credential-stuffing bursts, obviously headless clients. Agentic scanning presents none of those signals. The tempo is low, a handful of waves a day spread across hundreds of targets, and any single store sees only a small number of interactions. Rate limiters and reputation blocklists have little to act on.
Skimmer injection compounds the problem. The malicious script arrives through the checkout's own script chain, so it executes inside code the store already trusts, and the theft happens in the browser after the customer's data has been validated. Detection depends on monitoring payment-page integrity rather than on filtering inbound traffic.
Vendors selling bot mitigation price their products around request volume, which is exactly the dimension this campaign kept low. A defender buying more of the same capacity gains little against an attacker who never needed to generate noise in the first place.
The Wider Patching Week
Gambit's disclosure landed alongside several other urgent items. F5's BIG-IP APM carries a zero-day, CVE-2026-94127, that allows unauthenticated remote code execution, with a federal remediation deadline of 25 September. A GitLab issue-email weakness can be chained into code commits, and a public container-escape exploit exists for an unpatched Ubuntu kernel flaw. Security teams spent the same week triaging those, which is time not spent hunting low-volume checkout anomalies.
What to Watch
Gambit labels its report interim, and that qualifier matters. The 27 confirmed compromises and the 600,000-card count are floors set by what the firm could account for, so the real victim list is probably longer. Nothing in the advisory suggests the AI agent card skimming operation has stopped.
The number worth tracking next is the total spend, since the $25.46 average is what makes this model repeatable for other operators. For retailers, the practical question is whether checkout-page monitoring can flag a script that behaves normally until a customer submits a card. For shoppers, the record count already answers whether card details from these stores are in circulation.
Why This Matters
The campaign shows what changes when the cost of an attack drops to the price of a routine business expense. Card skimming used to demand enough manual effort to limit how many stores one operator could reach. Three open-source frameworks and a commodity model subscription removed that ceiling, and the technique is not tied to one retailer, one region or one payment platform. The next store breached will not be chosen for being an outlier; it will be chosen for being reachable.
Photo by Zeller HQ on Unsplash
Related Articles
- GS Retail Data Breach Draws $9.3M Fine After 1.66 Million Customer Records Leak
- The PaperCut AI Agent Attack Shows Identity Governance Is the Weak Link
- CrowdStrike AI Spending Surge Hits $1B as Cybersecurity Giant Bets on Agentic Defense
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.