Gambit details AI-agent operation behind theft of over 600,000 card records

Gadget Review

Cybersecurity firm Gambit Security says an operator used three AI agents to steal more than 600,000 unexpired payment-card records and compromise at least 27 companies; Gadget Review could not independently verify the findings.

Between Sept. 10 and 15, 2026, Gambit says the operator launched 105 attack projects and compromised at least 27 companies, at a recorded mean cost of about $25.46 per completed scan. The firm estimated operating costs at roughly $18,000 over four weeks. Strix scanned for vulnerable targets, Cairn attempted intrusions, and Hermes coordinated operations. After gaining access, agents inserted checkout-page code to capture card details. In one breach, Gambit says an agent deleted about 180 database tables, including backups, after extracting data.

Reported targets spanned hospitality, aviation, industrial supply and online retail, but Gambit named none. The same skimmer family appeared on more than 100 additional infected sites; evidence did not establish that all were retailers. Gambit assessed the operator as Chinese-speaking and financially motivated, while cautioning that language and tools do not establish nationality or government ties; its report found no evidence of Chinese government involvement. Gambit said it notified affected organizations and identified skimmers had been removed, but did not confirm complete remediation. No affected organization had publicly confirmed a breach at publication.

#AI-agent-payment-card-theft #Gambit-Security-AI-agent-campaign