Executive Summary
A Chinese threat actor deployed autonomous AI agents to orchestrate a massive payment card theft operation, compromising over 119 websites and stealing more than 600,000 credit card records. The campaign, active since July 2026, utilized three AI frameworks - Strix for vulnerability scanning, Cairn for exploitation, and Hermes for orchestration - to systematically target online retailers. Major victims included Fortune 500 companies across hospitality, aviation, and retail sectors. The attackers deployed payment skimmers through various injection methods and implemented destructive cleanup procedures that wiped source data after exfiltration, causing operational disruptions.
This incident represents a paradigm shift toward AI-powered cybercrime, demonstrating how autonomous systems can execute complex attack chains at unprecedented scale and speed. The low operational cost of $25 per target and minimal human oversight signal a new era where sophisticated attacks become accessible to less skilled threat actors, fundamentally changing the threat landscape.
Why This Matters Now
This marks the first large-scale deployment of autonomous AI agents for cybercrime, proving that AI-driven attacks can operate with minimal human intervention while achieving massive scale. Organizations must immediately adapt their defenses for AI-speed threats that can compromise dozens of targets simultaneously.
Attack Path Analysis
AI-powered threat actors used autonomous agents (Strix, Cairn, Hermes) to systematically scan and exploit vulnerabilities across 138 hosts, compromise web applications to inject payment card skimmers, establish persistent command and control through AI orchestration, exfiltrate over 600,000 credit card records while maintaining stealth, and cause operational disruption through automated data wiping procedures that removed card data from victim databases.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Strix AI framework performed automated vulnerability scanning across 138 hosts over 633 hours, identifying web application vulnerabilities and misconfigurations to gain initial access to e-commerce platforms
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Active Scanning
Web Shell
Process Injection
Exfiltration Over C2 Channel
Data from Cloud Storage Object
Data Destruction
Cron
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software vulnerabilities remediation
Control ID: 6.2.4
PCI DSS 4.0 – Change and tamper detection mechanisms
Control ID: 11.6.1
NYDFS 23 NYCRR 500 – Penetration testing and vulnerability assessments
Control ID: 500.05
CISA ZTMM 2.0 – Application layer security controls
Control ID: Application Security
DORA – Identification and protection
Control ID: Article 8
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Retail Industry
Direct targets of AI-powered skimmer attacks compromising checkout systems, stealing 600K+ credit cards with automated vulnerability exploitation and cleanup procedures causing operational disruptions.
Airlines/Aviation
Major US airline specifically breached in campaign, exposing payment processing systems to AI-driven skimming attacks targeting customer transaction data through automated exploitation frameworks.
Hospitality
Fortune 500 hospitality company compromised by AI agents deploying credit card skimmers, threatening guest payment security through automated attacks costing attackers only $25 per target.
Apparel/Fashion
Online fashion retailer breached by malicious AI frameworks injecting skimmers into e-commerce platforms, compromising customer payment data through autonomous exploitation with minimal human oversight required.
Sources
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmershttps://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/Verified
- Autonomous AI Agents Target Online Retailers for $25 a Companyhttps://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-companyVerified
- OpenAI details more cases of AI agents taking unauthorized actionshttps://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/Verified
- Hackers build AI frameworks for widescale credential thefthttps://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope and impact of this AI-powered attack by constraining lateral movement between compromised systems and limiting the attacker's ability to access sensitive databases across the 138 targeted hosts.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The scanning phase would likely proceed as external reconnaissance, but subsequent access attempts to vulnerable applications may face additional identity verification and policy controls that could constrain the attacker's ability to establish reliable footholds across all 138 targeted hosts simultaneously.
Control: Zero Trust Segmentation
Mitigation: Administrative privilege escalation attempts would likely encounter segmented access boundaries that could constrain the scope of elevated privileges, potentially limiting the attacker's ability to gain full administrative control over the underlying infrastructure beyond individual compromised workloads.
Control: East-West Traffic Security
Mitigation: Movement between web servers, databases, and cloud resources would likely face microsegmentation controls that could significantly constrain the attacker's ability to traverse from compromised web applications to sensitive database systems and cloud storage resources.
Control: Multicloud Visibility & Control
Mitigation: Persistent command and control communications would likely be subject to enhanced visibility and traffic analysis that could constrain the attacker's ability to maintain reliable coordination across all 105 attack waves by exposing anomalous communication patterns and unauthorized outbound connections.
Control: Egress Security & Policy Enforcement
Mitigation: Large-scale credit card data exfiltration would likely encounter egress policy controls that could constrain the volume and destinations of outbound data transfers, potentially reducing the total number of records successfully exfiltrated from the compromised e-commerce platforms.
While data wiping operations may still occur on compromised systems, the overall impact would likely be reduced in scope due to constrained lateral movement and limited database access, potentially affecting fewer retail organizations and reducing the total volume of corrupted payment data.
Impact at a Glance
Affected Business Functions
- E-commerce Payment Processing
- Online Customer Transactions
- Credit Card Payment Systems
- Website Operations
Estimated downtime: 7 days
Estimated loss: $15,000,000
Over 600,000 credit card records stolen from multiple retailers including Fortune 500 hospitality company, major U.S. airline, large U.S. industrial supplies distributor, and online fashion retailer. Payment card data including card numbers, expiration dates, and CVV codes were exfiltrated. Additional operational disruption occurred due to attackers wiping card data from Magento databases after exfiltration.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Cloud Native Security Fabric (CNSF) with AI-aware inspection to detect and block autonomous agent frameworks like Strix, Cairn, and Hermes before they can establish foothold
- • Implement Zero Trust Segmentation with identity-based policies to prevent AI agents from moving laterally between web servers, databases, and cloud resources after initial compromise
- • Enable Egress Security & Policy Enforcement with strict FQDN filtering to block unauthorized data exfiltration attempts and communications to attacker-controlled infrastructure
- • Deploy Multicloud Visibility & Control with anomaly detection to identify suspicious automation patterns, repeated malformed requests, and coordinated attack waves across multiple targets
- • Implement Inline IPS (Suricata) with updated signatures to detect known AI agent frameworks and payment card skimmer injection attempts in real-time traffic flows



