Gambit researchers have uncovered a large-scale cyberattack campaign that has stolen over 600,000 payment records since July 2026. The attack, driven by artificial intelligence, has targeted dozens of retail and service websites, using three autonomous AI tools to exploit vulnerabilities and extract sensitive data. The campaign highlights how AI can enable cybercriminals to conduct attacks more quickly, cheaply, and persistently than traditional methods. The attack began in July 2026 when a hacker deployed AI agents to target retail organizations globally, install skimming software to steal credit card information, and collect payment records. Since then, the AI systems have launched hundreds of attacks, compromising numerous companies and stealing data from at least 600,000 individuals. The campaign remains active, with the attackers continuing to target and breach websites as of the latest report. Gambit researchers were able to recover the attacker’s staging server and analyze the ongoing campaign. They observed the skimming tools still present on victim websites and examined logs and AI-generated instructions found on the server. Between September 10 and 15 alone, the AI agents launched 105 attacks and compromised 27 organizations to varying degrees. Some of the victims include a Fortune 500 hospitality company, a major U.S. airline, a large industrial supplies distributor, and an online fashion retailer. The attackers are believed to be financially motivated Chinese threat actors using three AI "harnesses"—frameworks that automate the attack process. These tools can operate almost entirely on their own, targeting around 10 companies per day for a cost of just a few dollars per attack. Over four weeks, the attackers spent about $7,000, with the total cost of the operation estimated at no more than $18,000. On average, each attack cost around $25. The AI tools used in the campaign include Strix, an open-source penetration testing tool, and Cairn, an autonomous pentest engine that runs for hours until it achieves its objective, such as gaining admin access. The most advanced tool, Hermes, functions as a console for managing attacks and includes features like persistent memory, a searchable archive of past attacks, and a web interface for control. The attackers used a Chinese AI model called "SOUL - Red Team Operator," which contained 78 attack skills. The human operator used short prompts in Chinese to direct the AI agents, often launching attacks or instructing them on next steps. Gambit researchers described the campaign as highly efficient, noting that the attackers achieved results far faster and more comprehensively than most human attackers could sustain. They warned that organizations must prepare for a new era of cyberattacks that are faster and more thorough, urging companies to adopt security strategies that can match AI’s speed and scale. Many of the affected organizations have been notified, and the skimming tools have been removed, though the long-term impact of the breaches remains to be seen.