Cybercriminals are deploying autonomous AI agent frameworks to target online retailers and steal payment card details at scale, according to research from cybersecurity firm Gambit Security. Their analysis reveals that the ongoing campaign has compromised at least 119 websites—including a Fortune 500 hospitality company, a major U.S. airline, and an online fashion retailer—exfiltrating over 600,000 valid credit card records.
These automated systems allow threat actors to scan, exploit, and infect target sites at a remarkably low operational cost, lowering the technical and financial barriers to large-scale cybercrime.
How the AI Credit Card Skimming Attack Works
In simple terms, a digital credit card skimmer acts like a hidden recording device inside an online checkout counter. Instead of physically tampering with a card reader, scammers use automated software tools to breach an e-commerce website’s backend servers.
Once inside, the software places invisible lines of malicious code directly on the payment page. When you enter your credit card number, expiration date, and security code to make a purchase, the hidden code silently copies your financial information and sends it to the attacker. Your order processes normally without any visible interruption.
Behind this campaign, threat actors use three specialized open-source AI frameworks to manage the intrusion without needing constant human oversight:
- Strix: Automatically scans websites to search for unpatched security vulnerabilities or unprotected doors into backend servers. Across an eight-day window, Strix logged 633 scanning hours across 138 website hosts.
- Cairn: Takes the security flaws discovered by Strix and uses them automatically to break through website defenses, giving the scammer administrative access.
- Hermes: Serves as an orchestration agent for the operation. Powered by advanced AI (Claude Opus 4.6), it makes real-time tactical decisions, directs the attack steps, installs the skimmers, and manages 121 operational skills.
The Low Cost and High Impact of AI-Driven Attacks
According to data published by Gambit Security, the attacker ran 105 distinct attack waves in a five-day span using brief instructions like “get to work.” The total infrastructure cost ranged between $12,000 and $18,000, averaging just $25.46 per targeted company. By driving the average cost down to tens of dollars per target, AI automation slashes the financial and technical barriers to cybercrime. Threat actors can now execute high-volume enterprise breaches at scale that previously required costly manual operations and dedicated technical teams.
Once inside, the AI agents inject malicious JavaScript skimmers into checkout forms, Google tag blocks, content delivery networks (CDNs), or server caches. The Hermes agent was also instructed to execute cleanup routines that wiped stolen payment fields directly from merchant databases, causing server errors and data loss for affected retailers. While this particular campaign compromised e-commerce websites, automated scripts can also target payment data directly on client devices, such as the browser-level threats highlighted in McAfee Labs research on wallet-swapping extension malware.
Warning Signs and Red Flags
Digital skimmers operate quietly within legitimate checkout pages, but technical anomalies can indicate a compromised payment form:
- Checkout latency or page crashes: The payment form freezes, stutters, or throws an error message while processing your transaction.
- Repeated payment prompts: The website requests that you re-enter your payment card details immediately after you submit them.
- Visual formatting errors: Payment entry fields display misaligned input boxes, mismatched fonts, or unexpected design changes compared to the rest of the site.
- Immediate transaction notifications: Your bank flags an unfamiliar charge or location seconds after you complete a purchase.
How to Protect Yourself From Digital Credit Card Skimmers
- Pay with third-party digital wallets. Complete purchases using Apple Pay, Google Pay, or PayPal. These payment services use encrypted tokenization, ensuring your actual credit card number is never transmitted to or stored on the merchant’s payment form.
- Use virtual credit cards. Generate temporary, single-use, or merchant-locked virtual card numbers through your bank or card issuer to prevent stolen card details from being reused elsewhere.
- Avoid saving payment information in merchant accounts. Input payment details manually for individual transactions rather than storing card numbers inside store customer profiles or retailer databases.
- Enable real-time transaction alerts. Turn on immediate push notifications or SMS alerts in your banking app for every account charge so you can identify unauthorized activity immediately.
What to Do If You’ve Already Been Targeted
If you suspect your credit card information was stolen or compromised in a digital skimming attack:
- Contact your bank or card issuer immediately. Report the compromised card, request an immediate cancellation, and dispute any unauthorized charges.
- Update your account credentials. Change passwords and turn on multi-factor authentication (MFA) across all financial accounts and shopping portals where you used the same login information.
- Place a credit freeze. Contact Equifax, Experian, and TransUnion to freeze your credit files, preventing unauthorized accounts from being opened in your name.
- Maintain transaction records. Retain bank statements, order confirmation emails, receipts, and the web URL of the merchant site where the purchase occurred.
- Create an official recovery plan. If personal identifying information (such as your Social Security number or date of birth) was exposed alongside financial details, submit a report to the FTC to get a recovery plan.
Reporting Credit Card Skimming and Staying Safe
Reporting stolen payment data helps law enforcement track malicious server infrastructure and disrupt automated threat networks. If you suspect your financial data was exposed on a compromised site, report the incident through official channels:
- FBI Internet Crime Complaint Center: Submit a formal incident report with ic3.
- Federal Trade Commission: Report payment fraud and scam activity to the FTC.
- Local Police Department: File a police report if required by your bank or insurance provider for fraud reimbursement claims.
- The Affected Merchant: Contact the retailer’s customer support or security team directly through their official domain.
While AI skimming attacks can be difficult to detect on the front end of retail websites, taking immediate action after a suspected exposure limits potential financial damage. By utilizing encrypted digital wallets, avoiding stored payment methods, and reviewing account statements regularly, you significantly reduce your exposure to AI-driven cybercrime.