Skip to main content

AI-Powered Campaign Targets Hundreds of Online Retailers

0
Critical
Campaign
Published: 09/24/2026 (09/24/2026, 12:48:14 UTC)
Source: SecurityWeek

Description

A financially motivated Chinese-speaking threat actor has conducted an AI-powered campaign targeting hundreds of online retailers since July 2026. The campaign uses three open source AI tools to automate vulnerability research, exploitation, and attack orchestration. Over 600,000 unexpired credit cards were stolen from two compromised companies, and skimmer scripts were injected into over 100 online stores. The attackers also gained access to several US firms and a Fortune 500 hospitality company. The campaign features dynamic attack paths chosen in real time and rapid compromise, often within hours. The threat actor used AI agents with persistent memory and extensive attack skills to orchestrate intrusions and cover tracks by deleting stolen data and backups. The campaign demonstrates a low-cost, scalable approach to cyberattacks leveraging autonomous AI agents.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 13:02:59 UTC

Technical Analysis

The campaign leverages three open source AI harnesses: Strix for vulnerability scanning, Cairn for autonomous penetration testing and attack execution, and Hermes for orchestration and persistence. Between August and September 2026, the attacker ran hundreds of scans and launched over 100 attack projects, compromising at least 27 companies. The attacker used AI to dynamically select attack paths and automate exploitation, resulting in varied tactics across victims. Stolen credit card data exceeded 600,000 records, primarily from US victims. Skimmer scripts were injected into checkout pages via multiple vectors including JavaScript files, Google tag blocks, AWS S3 buckets, and Kubernetes containers. The attacker maintained persistence by reappending skimmers after removal and deleting evidence from victim databases. The campaign highlights the emerging threat of AI-driven autonomous attacks at marginal operational cost.

Potential Impact

The campaign resulted in the theft of over 600,000 unexpired credit card records, including nearly 488,000 from US customers, posing significant financial and privacy risks. Multiple online retailers had skimmer scripts injected, exposing customers to payment data theft. Several companies, including a Fortune 500 hospitality firm and US-based businesses in various sectors, suffered unauthorized access. The rapid compromise timeline (hours to a day) and dynamic attack methods increased the difficulty of detection and response. The use of AI automation lowered the attacker's operational costs and increased attack scale and persistence.

Defensive Guidance

No official vendor advisory or patch information is provided for this campaign. As the attack exploits custom code vulnerabilities and injects skimmer scripts, affected organizations should conduct thorough security assessments of their web applications and infrastructure. Immediate actions include scanning for unauthorized scripts, verifying integrity of checkout page code, and reviewing access logs for suspicious activity. Organizations should also enhance monitoring for anomalous database deletions and unauthorized cron jobs. Given the use of open source AI tools by attackers, defenders should consider deploying AI-assisted detection and response capabilities. Patch status is not yet confirmed — check vendor advisories for any updates related to exploited vulnerabilities or compromised platforms.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.67,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/ai-powered-campaign-targets-hundreds-of-online-retailers/","fetched":true,"fetchedAt":"2026-09-24T13:02:47.943Z","wordCount":1459}

Threat ID: 6ab51f77f7a7c5410655df5e

Added to database: 09/24/2026, 13:02:47 UTC

Last enriched: 09/24/2026, 13:02:59 UTC

Last updated: 09/25/2026, 01:01:06 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses