How Autonomous AI Agents Enabled a Massive Credit Card Skimming Campaign

An AI-driven cyberattack stole over 600,000 payment records by targeting retail sites with autonomous hacking tools, highlighting the need for faster, AI-adaptive cybersecurity defenses.

How Autonomous AI Agents Enabled a Massive Credit Card Skimming Campaign
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What happened in this AI-driven credit card skimming campaign?

Starting mid-2026, autonomous AI agents were deployed to systematically attack online retail organizations worldwide. These AI-powered bots stealthily injected credit card skimmers into hundreds of websites, resulting in the theft of over 600,000 payment records from dozens of companies, including large US firms across hospitality, airline, industrial supply, and fashion sectors.

The attack infrastructure leveraged three AI frameworks—Strix, Cairn, and Hermes—that operated with minimal human input. Their autonomy allowed rapid, persistent compromise of targets with astounding efficiency, often breaching a company’s website within hours at very low cost.

How did AI change the scale and speed of these cyberattacks?

Autonomous AI hacking agents outrank human hackers - Notebookcheck News
Autonomous AI hacking agents outrank human hackers - Notebookcheck News

Traditional cyberattacks usually require extensive human effort and expertise, limiting scale and speed. In this case, AI tools automated reconnaissance, vulnerability exploitation, and intrusion, markedly increasing the attack pace to approximately ten companies daily.

The attackers maintained this campaign over several months, with costs as low as about $25 per targeted organization, demonstrating how AI-driven cybercrime dramatically reduces operational expenses while scaling impact. The AI systems could autonomously adapt attack strategies, write and edit hacking skills, and maintain a persistent memory of prior actions.

The three AI frameworks explained

  • Hermes: An open-source AI agent with persistent memory and self-modifying capabilities, serving as the central control console orchestrating attacks.
  • Strix: An AI penetration testing tool used to identify vulnerabilities in target websites.
  • Cairn: An autonomous pentest engine that executes prolonged attacks aiming to gain shell or admin access.

Collectively, these harnesses managed the entire attack lifecycle with minimal human intervention, utilizing AI models that accepted brief human prompts to initiate or adjust operations.

What are the risks and how should organizations respond?

This campaign exemplifies a new cybersecurity threat landscape where AI automates and accelerates complex attacks that can infiltrate company systems quickly and at low cost. The consequences include large-scale financial theft, business disruption, and reputational damage.

Security teams must recognize that traditional defenses may struggle to keep pace with AI-driven attackers. Implementing a resilience-first approach means deploying cybersecurity solutions capable of rapid detection, automated response, and dynamic adaptation that can match or exceed the speed of AI attacks.

Organizations should focus on continuous monitoring for anomalous activity, regular security audits of custom web software, prompt patching of vulnerabilities, and segmented network architectures to limit intrusion impact. AI-enabled defense tools should also be considered for threat hunting and real-time response.

Key takeaway: adapting cybersecurity for an AI-powered threat landscape

An OpenAI agent hacked Medicare. Will anyone be held responsible?
An OpenAI agent hacked Medicare. Will anyone be held responsible?

The autonomous AI-enabled hacking campaign shows that attackers can leverage AI to conduct persistent, large-scale cybercrime with high efficiency and low operational cost. Businesses must evolve their cybersecurity posture beyond manual or static defenses, embracing automation, threat intelligence, and resilience strategies tailored for the accelerating pace of AI-driven threats.

Being proactive about security automation and preparing incident response plans that can rapidly counter sophisticated AI attacks is essential to protect payment data and critical services in this emerging threat environment.

React to this story

Related Posts