AI News Feed
Market watch
Cybersecurity

Gambit Says Chinese Threat Actors Used AI Agents to Steal 600,000 Payment Records

Gambit says AI agents stole at least 600,000 payment records since July 2026 and compromised dozens of organizations.

Gambit said the bots launched hundreds of attack projects, compromised dozens of organizations, and stole at least 600,000 payment records. It recovered the operator's staging server and used it to reconstruct the campaign. The researchers also observed skimmers live on victim websites and reviewed logs and AI claims found on the attacker's server. In just five days, between September 10 and September 15, the agents made 105 attack waves and compromised 27 organizations 'to varying degrees,' according to the report.

Victims include a Fortune 500 hospitality company, a 'major' US airline, a large private US industrial supplies distributor, and a US online fashion retailer. One of the AI tools used a website ranking service to produce a list of potential targets, focusing primarily on organizations running custom-built software.

Gambit believes the attackers are financially motivated Chinese threat actors. They used three AI 'harnesses' that can run almost the entire attack chain autonomously, striking around 10 companies a day for a handful of dollars per company. In four weeks, the attackers spent around $7,000, meaning the operation's entire cost so far was no more than $18,000, or about $25 per target.

'Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company,' Gambit's researchers said. 'The operator's own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.'

The researchers said access, where achieved, usually took less than a day and in many cases just a few hours. They also detected instructions in the attacker's playbook that could disrupt a company's operations through data deletion or cleanup procedures run by the agent, and said this had happened in some of the breaches.

The three harnesses are called Strix, Cairn, and Hermes. Gambit described Hermes as an open-source autonomous AI agent with persistent memory, skills it wrote and edited itself, a searchable archive of past sessions, scheduled jobs, and a web console. On the staging server analyzed by the researchers, it loaded a Chinese system persona called 'SOUL - Red Team Operator,' which contained 121 skills, including 78 attack skills.

'Hermes is the operator's console for orchestrating the activity and for direct hacking activities,' Gambit explained. It used Anthropic's opus-4.6 after newer models refused its requests, with 1,951 prompts typed by the human across 260 sessions, or only a few prompts per target. The human prompts were short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or directing what to do after achieving access.

Strix is an open-source AI pentest tool, while Cairn is an autonomous pentest engine. Cairn receives target domains and an objective, such as getting a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. It used DeepSeek v4.1 Flash, according to the report.

Gambit described the campaign as very low cost, with patience, persistence, and creativity that most human attackers would be 'unlikely to sustain,' achieving 'far greater results, far faster.' The researchers urged organizations to 'adapt to a reality where attacks are significantly faster and more comprehensive,' adopt a resilience-first mentality, and deploy a security stack that can match AI on speed. Many affected organizations were notified and the skimmers were removed, they said.