Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news
ai

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

A financially motivated threat actor has weaponised open-source AI agent frameworks to conduct large-scale attacks against online retailers, stealing over 600,000 credit card records and deploying skimmers across 119+ websites since July 2026. The campaign operates with remarkable efficiency: using three AI tools (Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes for orchestration), a single operator with minimal technical intervention has launched over 100 attack waves in five days, compromising at least 27 companies. The attacker prioritised targets running custom software and used traffic-ranking services to identify high-value victims, including a Fortune 500 hospitality company, major U.S. airline, and industrial distributor. What distinguishes this campaign is its operational cost—approximately $25 per target, with total expenses estimated between $12,000 and $18,000 over four weeks—making AI-powered attacks economically viable even for less sophisticated threat actors.

The implications for CX teams are twofold and urgent. First, the attack methodology directly threatens the infrastructure underpinning customer data handling: skimmers were injected through multiple vectors including compromised JavaScript files, poisoned CDNs, altered Kubernetes deployments, and database manipulation. For teams managing customer interactions through platforms like Zendesk or Salesforce, this signals that payment data security cannot be treated as peripheral to CX operations—it is foundational. Second, the attacker's cleanup routines that wiped card data from Magento databases after exfiltration created operational disruptions at target retailers, suggesting that a breach may manifest not just as data theft but as system instability that directly impacts customer service delivery. As organisations increasingly deploy AI agents to handle customer interactions and transactions, the question becomes acute: how do CX teams validate that their AI-powered workflows—whether for sales, support, or payment processing—cannot be hijacked or exploited by autonomous attack agents operating at machine speed?

The campaign exposes a critical vulnerability in the current AI agent ecosystem: the low barrier to entry for attackers combined with the high autonomy granted to these systems. The operator provided only brief instructions before letting AI agents execute complex attack chains independently, suggesting that defenders cannot rely on detecting human-directed activity. For support leaders and CX consultants, this means security cannot remain siloed within IT; it requires embedding threat awareness into how customer-facing systems are architected, monitored, and recovered from. The precedent is clear: as AI agents become standard in CX platforms, so too will they become standard in attack chains.