A Chinese-speaking cybercriminal is reportedly using autonomous AI agents to attack online retailers at a pace that would be difficult for a human operator to maintain. According to research from Gambit Security, the campaign has compromised more than 100 websites with payment-card skimmers and resulted in the theft of more than 600,000 credit card records.
The United States accounts for the overwhelming majority of the exposed cards, with roughly 488,000 records reportedly belonging to U.S. customers. Thousands of additional cards were linked to customers in the United Arab Emirates, Saudi Arabia, the United Kingdom, and other countries.
What makes the campaign particularly concerning is its heavy reliance on AI automation. The attacker reportedly uses multiple AI-powered systems to perform tasks throughout the intrusion process, allowing attacks to move from initial compromise to data theft in hours. Gambit estimates the AI-related cost averaged roughly $25 per targeted company.
During a five-day period between September 10 and September 15, the operation reportedly launched 105 attacks and compromised 27 organizations to varying degrees. Gambit says the targets included companies in hospitality, aviation, industrial supplies, and online retail.
The campaign also targets Magento databases. After payment information is stolen, the AI agents can reportedly be instructed to delete card data from compromised systems as part of a cleanup process. In at least one incident, Gambit said the cleanup operation caused additional damage to the victim’s data.
The findings highlight an emerging cybersecurity challenge: AI can give individual attackers the ability to automate reconnaissance, exploitation, data theft, and post-attack activity across numerous targets simultaneously. Gambit’s other recent threat research has also documented attackers using AI for scripting, exploitation, infrastructure management, and interactive intrusion activity.
For online retailers, the campaign reinforces the importance of rapidly patching e-commerce platforms, monitoring website files for unauthorized changes, protecting administrative accounts with MFA, and watching payment infrastructure for suspicious scripts or unexpected database activity.

