{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0551",
  "aliases": [],
  "published": "2026-09-22T00:00:00Z",
  "firstReported": {
    "date": "2026-09-22",
    "url": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company",
    "publisher": "Eyal Sela, Gambit Security"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Three open-source attack agents run by one operator stole at least 600,000 card details and planted skimmers on retailer sites; one agent also dropped 180 tables, backups included.",
  "details": "## What\n\nGambit Security's interim report says an operator ran three open-source AI harnesses through almost the entire attack chain against online retailers: Strix for vulnerability search, Cairn for autonomous exploitation and Hermes to orchestrate, with 1,951 human prompts across 260 sessions, only a few per target. Hermes used Anthropic's Opus 4.6 after newer models refused its requests; Strix ran on GLM 5.2 and later DeepSeek v4 Pro, and Cairn on DeepSeek v4.1 Flash, with model access through OpenRouter. One of the operator's main objectives was injecting card-stealing skimmers into checkout pages. Gambit counts at least 600,000 unexpired card details stolen from two companies, skimmers ordered against at least 27 named victims and confirmed on 19, and more than 100 further websites carrying a skimmer associated with the campaign. Data loss came two ways: an operator-written skill wiped card fields after extraction, and an agent matching table names too broadly dropped 180 tables at one retailer, including backup tables its administrators had made.\n\n## Detection\n\nGambit bases its account on the attacker's staging server, live skimmers and the attacker-side logs, and warns that a few errors are possible. Recorded from Gambit's report and its researcher's posts on X. Not recreated in a lab.\n\n## Fix\n\nSeparate data access from cleanup, require review for retailer changes, and keep cardholder data outside unattended agent reach.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "strix"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "cairn"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "hermes"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Model",
        "name": "claude-opus-4.6"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Model",
        "name": "glm-5.2"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Model",
        "name": "deepseek-v4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
    },
    {
      "type": "REPORT",
      "url": "https://x.com/eyalsela/status/2102373749110587443"
    },
    {
      "type": "REPORT",
      "url": "https://x.com/eyalsela/status/2102421394965360909"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "data-exfiltration",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-359",
        "CWE-693"
      ],
      "taxonomy": {
        "atlas": [
          "AML.T0117",
          "AML.T0049"
        ]
      },
      "noCveReason": "No code defect is asserted: the harm arose from an attacker-directed agent campaign.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "exfiltration"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/"
        }
      ],
      "fix": {
        "summary": "The operator ran the attack, so victims depend on Anthropic and OpenRouter cutting off the harnesses and on backups kept outside the production database.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "anthropic.opus-4-6",
            "to": "refuses the requests newer models refused",
            "why": "Recommended: Hermes switched to Opus 4.6 after newer models refused its requests.",
            "owner": "model-provider"
          },
          {
            "type": "reconfigure",
            "target": "openrouter.accounts",
            "to": "detects and cuts off accounts driving attack harnesses",
            "why": "Recommended: all three harnesses reached their models through OpenRouter.",
            "owner": "model-provider"
          },
          {
            "type": "reconfigure",
            "target": "database.backups",
            "to": "kept outside the production database",
            "why": "One agent dropped 180 of the targeted organisation's tables, its backup tables among them.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Strix, Cairn and Hermes, three open-source AI harnesses",
          "any": false,
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "model": {
          "value": "Hermes: Claude Opus 4.6, after newer models refused its requests; Strix: GLM 5.2, later DeepSeek v4 Pro; Cairn: DeepSeek v4.1 Flash; all through OpenRouter",
          "any": false,
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "goal": {
          "value": "Inject card-stealing skimmer scripts into online shops' checkout pages",
          "stated": true,
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "tools": {
          "value": "Strix for vulnerability search, Cairn for autonomous exploitation given target domains and an objective such as a shell or admin access, and Hermes orchestrating with attack skills",
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "approval": {
          "value": "The harnesses ran almost the entire attack chain autonomously; the human typed 1,951 prompts across 260 sessions, only a few per target",
          "mode": "auto-approve",
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "inputControl": "operator",
        "agentAction": "The agents exploit retailer sites, extract card data and install skimmers; one, matching table names too broadly, drops 180 tables including the victim's backup tables.",
        "harm": "data-exfiltration",
        "divergence": "decomposed-misuse",
        "reach": {
          "value": "Retailer websites and checkout pages, card data, and in one documented chain AWS Secrets Manager, a Magento database on Aurora, S3 and CDN buckets and Kubernetes deployments",
          "kinds": [
            "network",
            "payment-method",
            "project-files",
            "production-database",
            "backups",
            "cloud-credentials"
          ],
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "condition": {
          "value": "When short operator instructions set the harnesses running autonomously between prompts, at a tempo no human operator sustains",
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "recovery": {
          "value": "Not undone: Gambit passed the stolen card data to Overwatch Data to notify issuers and helped take down infrastructure, but says the campaign is still running.",
          "outcome": "unrecovered",
          "status": "confirmed",
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        },
        "scale": {
          "statement": "At least 600,000 unexpired card details from two companies",
          "unit": "records",
          "value": 600000,
          "source": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "researcher",
        "primary": [
          {
            "url": "https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company",
            "kind": "researcher-report",
            "party": "Eyal Sela, Gambit Security"
          },
          {
            "url": "https://x.com/eyalsela/status/2102373749110587443",
            "kind": "researcher-report",
            "party": "Eyal Sela (@eyalsela)"
          },
          {
            "url": "https://x.com/eyalsela/status/2102421394965360909",
            "kind": "researcher-report",
            "party": "Eyal Sela (@eyalsela)"
          }
        ]
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/",
            "type": "research",
            "note": "Researchers reported direct evidence from the campaign's staging server."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
