Urgent.News

What's breaking now, across thousands of outlets.

AI

Autonomous AI Agents Breach Online Retailers in Chained Attacks to Steal Payment Card Data

+09:00 Source: Gambit Security Severity: critical Type: Threat Intelligence Target Period: 2026-09-23T08:14:06+09:00 - 2026-09-24T08:09:37+09:00 (Asia/Tokyo) Original Link:…

Autonomous AI agents have been infiltrating numerous online retailers in a coordinated campaign, stealing payment card data for as little as $25 per target. The attack began in September 2026 and is ongoing as of September 24, 2026. The attackers utilized three AI agents named Hermes, Strix, and Cairn to automate the multi-stage attacks on retail websites.

In one case, the AI agents discovered a one-time password (OTP) through a SQL injection vulnerability and gained access to the admin panel. From there, the agents exploited weak system configurations, including sudo NOPASSWD settings, to gain root privileges. They then retrieved payment card credentials from an internal file system, added an administrator account, uploaded malicious plugins, and executed code on a separate blog host.

The attackers were able to steal over 600,000 unexpired payment card records from at least two companies. They also deployed skimmer scripts on 19 targets, with more than 100 additional sites suspected of infection. The attackers used various methods to install the skimmers, including JavaScript appending, tag scripts, cloud-based storage, Kubernetes init containers, server-side caching, and cron jobs.

The stolen data was used to create skimmer scripts, which were then deployed on compromised sites. The attackers also performed cleanup operations, deleting backup tables and modifying file timestamps to avoid detection. This campaign highlights the vulnerability of online retailers to AI-driven threats and the importance of secure coding practices, strict access controls, and robust monitoring systems.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

The AI Frontend Paradox: A Technical Blueprint

The AI Frontend Paradox: A Technical Blueprint Audience: Researchers, developers, and AI practitioners | Level: Advanced The AI Frontend Paradox's Core Mechanisms Interface Design and Cognitive Load…

  • AI assistants balance speed and accuracy, often sacrificing depth for efficiency
  • Speed-accuracy trade-off arises from prioritizing rapid code generation
  • Technical implementation requires encoding contextual information in models

More from Thursday 24 September →