Security researchers disclosed an attack campaign on September 24, 2026, in which threat actors used three open-source AI agent frameworks to autonomously compromise over 100 online retailer websites and steal more than 600,000 credit card records. The campaign targeted a Fortune 500 hospitality company, a major U.S. airline, and 25 other organizations using AI harnesses that performed vulnerability research, exploitation, and attack orchestration with minimal human oversight.
Three Open-Source AI Frameworks Automate End-to-End Attacks
The campaign employed three distinct open-source AI agent frameworks to automate the complete attack lifecycle. These AI harnesses conducted vulnerability scanning against target websites, identified exploitable weaknesses, developed working exploits, and deployed payment card skimmers to harvest customer credit card data during checkout—all with minimal human intervention. The autonomous agents handled tasks that previously required skilled human attackers, lowering the technical barrier for large-scale web compromise campaigns.
Security researchers characterize this as the first documented large-scale use of AI harnesses for end-to-end attack automation. While individual attack steps have been automated for years, the integration of AI agents that can autonomously move from reconnaissance through exploitation to data theft represents a significant escalation in attacker capabilities. The frameworks allow operators to launch attacks at a scale that would be prohibitively expensive using traditional manual or semi-automated methods.
Attack Economics: $25 Per Vulnerability Scan Enables Mass Targeting
The campaign’s economics highlight the cost efficiency AI agents provide to attackers. Security researchers report the attacker’s AI bill averaged just $25 per completed vulnerability scan. This remarkably low cost-per-target enables mass scanning and exploitation at a scale that would be prohibitively expensive using human operators or traditional automation tools.
At $25 per scan across more than 100 compromised retailers, the attacker’s total AI infrastructure cost likely remained under $3,000—a negligible expense against the potential revenue from 600,000 stolen credit card records. Even if the attacker monetizes only a fraction of the stolen cards through fraud or resale on underground markets, the return on investment vastly exceeds the AI tooling costs. This economic model creates strong incentives for widespread adoption of AI-powered attack automation across the cybercrime ecosystem.
Fortune 500 Hospitality, Major Airline, and 25 Other Organizations Targeted
The disclosed victim list includes a Fortune 500 hospitality company, a major U.S. airline, and 25 other named organizations, alongside the broader tally of over 100 compromised online retailer websites. The targeting of large enterprises alongside smaller retailers suggests the AI agents performed indiscriminate scanning rather than focusing exclusively on high-value or poorly defended targets.
This opportunistic approach reflects how autonomous agents change attacker behavior. Instead of carefully selecting targets based on value and likelihood of success, attackers can deploy AI agents to scan thousands of potential victims and exploit whatever vulnerabilities the agents discover. The human attacker’s role shifts from conducting each attack to managing the AI systems that find and compromise targets automatically—a fundamentally different operational model than traditional targeted intrusion.
Web Skimmers Harvested Over 600,000 Credit Card Records
Once the AI agents compromised a retailer’s website, the attacker deployed payment card skimmers—malicious scripts injected into checkout pages that intercept credit card numbers, CVV codes, and billing information as customers enter it. These skimmers operate silently in the background of legitimate payment forms, sending captured card data to attacker-controlled servers while allowing transactions to complete normally so victims and retailers remain unaware of the compromise.
The 600,000-card figure represents confirmed theft from the disclosed campaign, but the actual scope may be larger. Skimmer campaigns typically run for weeks or months before detection, and the automated nature of this attack suggests the AI agents could have deployed skimmers on additional sites not yet identified by security researchers. The scale of the theft—over half a million compromised cards—places this among the most significant payment card compromise campaigns disclosed in recent years.
Defender Implications: AI-Powered Attacks Lower Skill Requirements for Mass Compromise
The campaign demonstrates that open-source AI agent frameworks have advanced to the point where financially motivated attackers can conduct sophisticated vulnerability research and exploitation at scale without deep technical expertise. The $25-per-scan cost and autonomous operation create conditions for a proliferation of AI-powered attack campaigns, as the tooling becomes accessible to any attacker with sufficient funds to pay cloud AI API bills.
Affected retailers should immediately scan for web skimmers and review web application logs for signs of automated vulnerability scanning. Organizations running e-commerce platforms face an adversary landscape in which attackers can now deploy persistent, autonomous agents that continuously probe for new vulnerabilities and deploy skimmers within hours of finding an exploitable weakness—a faster attack tempo than human-driven campaigns and one that demands equally automated detection and response capabilities.
The campaign also highlights the dual-use nature of AI agent frameworks. The same open-source tools designed to automate security research, software testing, and system administration tasks can be repurposed for malicious automation. As these frameworks become more capable and easier to use, the barrier to entry for sophisticated attacks will continue to drop, creating an expanding threat landscape that defenders must adapt to counter.
