AI-Driven Cyberattacks Compromise 600,000 Credit Cards in Massive Retailer Breach
September 23, 2026
A largely autonomous, AI-driven attack campaign targeted hundreds of online retailers from early to mid-September 2026, compromising at least 27 companies and exfiltrating data from more than 600,000 non-expired credit cards.
Researchers note the operation relied on three open-source AI harnesses—Strix for vulnerability hunting, Cairn as the autonomous exploitation engine, and Hermes as the orchestrator with memory and specialized skills—to conduct automated, low-cost incursions since mid-2026.
The attackers used autonomous AI agents to perform vulnerability research, exploitation, and orchestration, executing end-to-end attack chains with minimal human input across numerous targets.
Defensive guidance stresses resilience and rapid recovery, advocating pre-tested recovery plans to restore essential systems even if backups or data stores are compromised or deleted.
Skimming techniques varied and were designed to blend in, including loader injections in JavaScript files, CDN-hosted payloads, Kubernetes initContainers, and cron-based reinfections.
Attack methods differed by victim but commonly involved JavaScript tags, S3/CDN deployment, Kubernetes components, database manipulation, and cron-based redeployments, with attackers deleting data and faking timestamps to evade detection.
A dangerous feature was a data-deletion routine that could erase backups and staging tables, risking irreversible loss for victims.
The operation achieved rapid compromises at low cost—roughly $25 per target on average—and typically completed breaches in under a day, complicating timely remediation for defenders.
Analysts corroborated findings using staging servers, live checks, and logs, acknowledging AI-generated details may be imperfect but supported by corroborating evidence.
Observables show checkout pages appeared normal while card data was exfiltrated in the background, with outbound connections to skimmer endpoints and new external domains detected.
In at least one case, an attack path progressed from SQL injection to OTP access, file uploads, remote code execution via sudo NOPASSWD, WordPress credential access, administrator creation, plugin upload, and retrieval of 46 AWS Secrets Manager secrets enabling Magento/Aurora access.
Another example chain used SQL injection to harvest a plaintext one-time password, gain web-panel access, deploy a web shell, escalate privileges, and obtain AWS credentials.
Summary based on 7 sources
Get a daily email with more Tech stories
Sources

Hackread - Cybersecurity News, Data Breaches, AI and More • Sep 23, 2026
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
DEV Community • Sep 24, 2026
Autonomous AI Agents Breach Online Retailers in Chained Attacks to Steal Payment Card Data
