Skip to content

All the news that matters, in plain English.

Latest
  1. Anti-migrant activist Daniel Thomas arrested on suspicion of criminal damage after Channel dinghy slashing
  2. US cities take on the FCC over its plan to override local broadband rules
  3. Glasgow City Council to sack and rehire more than 20,000 staff in pay row
  4. Susan Sarandon and Hannah Einbinder among about 100 arrested at Netanyahu UN protest
  5. Finnish president Stubb pleads with Musk to let Ukraine use Starlink against Russian missile launchers
  6. Bank of England rate-setters warn of 'sparks in the tinderbox' as hike bets grow
  7. US Coast Guard suspends search for Carnival Panorama passenger Thomas Gigler
  8. Venezuela's Rodríguez promises elections in UNGA debut but gives no date

Technology

AI agents raided online retailers and stole 600,000 credit cards, Gambit says

Gambit Security says a financially motivated, likely Chinese-speaking operator used three open-source AI agents to raid online retailers at about $25 per target, stealing more than 600,000 unexpired card records in a campaign running since July 2026.

A financially motivated threat actor, likely Chinese-speaking, has been using autonomous AI agents to raid online retailers at about $25 per target, according to a Gambit Security threat-intelligence report of 22 September 2026, reconstructed from the attacker’s exposed staging server.

Gambit says the campaign has run since at least July 2026 and was still active at disclosure. Between 10 and 15 September the operator launched 105 attack projects and compromised at least 27 companies, typing just 1,951 Chinese prompts across 260 sessions while the agents handled reconnaissance, exploitation, extraction and cleanup.

Three open-source AI harnesses formed the attack stack: Strix for vulnerability discovery, Cairn for autonomous exploitation, and Hermes for campaign orchestration — the last carrying 121 skills, 78 attack-oriented. The operator used DeepSeek and Kimi models via OpenRouter, falling back to an older Claude Opus 4.6 where newer models refused the requests.

Gambit reports more than 600,000 unexpired credit card records were exfiltrated from two victim companies, with skimmers confirmed on 19 checkout pages and linked skimmer code on more than 100 further sites. Some 488,372 cards — 79% — belonged to US holders, with the rest across the UAE, Saudi Arabia, the UK and New Zealand; anti-fraud specialists confirmed most were still active.

Victims include a Fortune 500 hospitality company, a major US airline, an industrial supplies distributor and an online fashion retailer. Gambit put total AI model spend at $12,000–$18,000. In one case a cleanup routine at a bicycle retailer dropped 180 database tables, including administrator-created backups.

Sources

More on this topic: all Technology stories

Get Flip News by email

This opens your email app — we add you manually. No account, no spam, no third parties.