Since July 2026, an attacker has let autonomous AI agents break into retail websites around the world, plant credit card skimmers and collect payment data, TechRadar reported on 24 September, citing the security firm Gambit. At least 600,000 payment records have been stolen, and the researchers said the campaign was still running.
What the researchers found
Gambit says it recovered the operator’s staging server and reconstructed the campaign from its logs. In five days alone, 10 to 15 September, the agents ran 105 attack waves and compromised 27 organisations “to varying degrees”. Victims include a Fortune 500 hospitality company, a “major” US airline, a large US industrial supplies distributor and a US online fashion retailer. One tool picked targets from a website ranking service, favouring sites running custom-built software.
The operator, whom Gambit believes to be a financially motivated Chinese group, used three AI “harnesses” that can run almost the whole attack chain on their own, hitting around ten companies a day. The operator’s console, Hermes, used Anthropic’s opus-4.6 after newer models refused its requests, driven by 1,951 short prompts typed in Chinese across 260 sessions. Another engine, Cairn, used DeepSeek v4.1 Flash. Where access was achieved, Gambit said, it usually took less than a day, sometimes a few hours, and in some breaches the agent’s clean-up steps deleted data.
The cost is the part that should worry everyone: around $7,000 over four weeks, no more than $18,000 for the whole operation so far, and a mean of $25.46 per target across 101 completed scans. Many of the affected organisations were notified and the skimmers removed, the researchers said.
What this means for you
A web skimmer lives on the shop’s website, not on your computer. When you type your card number into a compromised checkout page, a script planted by the attacker copies it as you type. Nothing needs to be installed on your Mac, and a careful shopper on a clean machine can still be caught. What changes with AI agents is scale: if attacking a shop costs a few dollars, many more shops get attacked.
- Prefer a payment method that doesn’t hand the shop your real card number, such as Apple Pay, or a virtual card from your bank.
- Turn on instant transaction alerts in your banking app so an unknown charge reaches you in minutes, not at the end of the month.
- Check your statements, and report anything you don’t recognise straight away.
- Be more careful on small or unfamiliar shops with custom checkouts; the researchers say the tools favoured sites running custom-built software.
Where FireAI fits: honestly, mostly not here
This attack happens on the retailers’ servers, so a firewall on your Mac cannot stop it, and we won’t pretend otherwise. FireAI decides which apps on your Mac may connect where; it doesn’t inspect the pages your browser loads or the scripts a shop runs inside them.
Where FireAI does help is the other half of the same trend. The tools in this campaign are ordinary software that can run on anyone’s computer, and AI agents are arriving on Macs too. FireAI asks before any new app or agent connects to the internet, shows every destination on the world map, and in Under attack mode lets only apps you’ve explicitly allowed connect at all. Its own AI runs on your Mac. Download FireAI and try it free for 17 days. FireAI is made by HisnLabs.