Detect Deepfakesby Resemble AI
Agentic AI attack

AI agents breach online retailers

Gambit documented autonomous intrusions, stolen payment records, and injected checkout skimmers.

Reported date
Sep 22, 2026
Target
Multiple online retailers
Agent type
Multiple AI agents
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 23, 2026 · 1 min read

Gambit Security reported an ongoing criminal campaign in which one operator delegated intrusions to three autonomous systems: Hermes, Strix, and Cairn. The tools searched for weaknesses, selected attack paths, and pursued access largely unattended.

Investigators examined a staging server. During September 10–15, 2026, the operator launched 105 attack projects, with differing levels of compromise at 27 or more companies. The wider campaign had operated since July.

The documented damage included payment information stolen from two businesses and malicious checkout scripts placed on retailers’ websites. Gambit counted more than 600,000 unexpired payment-card records. One cleanup operation erased 180 tables, including backups, at a bicycle retailer.

Gambit corroborated parts of its reconstruction using recovered stolen material and compromised websites. Other findings depended partly on agent logs, so the company cautioned that its interim account could contain errors. This entry uses the September 22 publication date because the campaign’s precise starting day is unknown.

Evidence in the reporting

Incident evidence
27 companies were compromised to varying degrees
Agent involvement
Three AI harnesses ran almost the entire attack chain autonomously

Sources