Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-24 · updated: 2026-09-24 · tags: [incident, retail] · confidence: high · severity: medium · affected_sectors: [retail] · au_impact: true

Gambit has documented a financially motivated campaign, active since at least July and ongoing as of 22 September, in which a human operator gave open-source AI agent frameworks campaign goals and let them run the attack chain against tens of companies per day. The stack is three tools: Strix, a penetration-testing framework used for scanning and vulnerability discovery; Cairn, an autonomous exploitation engine tasked with objectives such as obtaining a shell or administrator access; and Hermes, which handled orchestration, post-exploitation and tactical decisions using claude-opus-4.6 and carried a persona, "SOUL - Red Team Operator", with 121 skills, 78 of them attack-related. Strix ran 146 times against 138 hosts between 23 and 31 August, accumulating 633 scanning hours, and between 10 and 15 September the operator launched 105 distinct attack waves, succeeding to varying degrees on at least 27 organisations; the campaign compromised at least 119 sites with card skimmers and stole more than 600,000 valid card details from two companies, reaching a Fortune 500 hospitality firm, a major US airline, an industrial supplies distributor and an online fashion retailer. Skimmers were planted by appending to legitimate JavaScript, injecting script tags into checkout pages and Google tag blocks, poisoning S3/CDN content and server-side caches, altering database fields and Kubernetes deployments, and using cron jobs to restore the skimmer after removal.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-09-24
Source BleepingComputer
Reliability Tier 2