Cyber Crime Put AI on the Payroll
gambit security got hold of the staging server behind a card-theft campaign and rebuilt the whole thing from the inside. the operator's own logs, the exfiltrated data, the agent sessions. what gambit found is that a version of the ai driven crime story has actually arrived. it is just not the version people spent years predicting.
the evidence points to a likely single chinese speaking operator behind the campaign. there was a system persona written in chinese, along with prompts written in the same language. now this is merely language evidence and nothing more. it could be legit, or it could be a false flag. we need to be cautious about attribution at this point. not only that, but no threat actor group name. no nation state claim. just a financially motivated person running an illicit business.
since july 2026, that one operator pointed a stack of open-source ai agent frameworks at various online retailers. those agents scanned for weaknesses, developed an attack path, broke in, and the campaign was ultimately tied to card skimmers on at least 119 sites. between september 10 and 15 they launched 105 attack projects, compromising at least 27 companies to varying degrees across 5 days.
the campaign pulled in more than 600,000 unexpired credit card records. 488,372 of them were us-issued cards, roughly 79% of the total. the remainder was spread globally. those 600,000 records came from just two of the victim companies.
the operator spent roughly $25 per target. the average cost was $25.46 across 101 completed scans, from as low as $3.13 to as high as $79.31. gambit estimated the operator spent somewhere between $12,000 and $18,000 on model usage across the wider campaign.
that is the story. this time is not about a machine waking up and deciding to commit a crime. rather, a person decided to commit crime, and rented the labor for $25 per company.
the operator sent 1,951 prompts across 260 sessions, mostly in chinese. not that the language has a material effect on the outcome, but i mention it to demonstrate the possibility of who was behind the attack. nevertheless, a human was in the loop the whole time. the difference here is the human was not choosing every exploit or walking the agent through every step. cairn could run for hours on its own, continually probing the target and selecting attack paths until it gained access, timed out, or gave up. the human said what. the agent increasingly worked out how.
that distinction matters for defenders.
the tooling was not exotic. three open-source harnesses, each doing one job. hermes ran the console and the campaign, kept persistent memory, and wrote its own skills. by the end it had 121 of them, 78 built for attacking. strix did the scanning, 146 runs against 138 hosts in a single week. cairn did the breaking in.
underneath, the operator mixed models the way a bartender wields spirits in a speakeasy. anthropic's claude opus 4.6 in one place. glm 5.2 and deepseek in others. western frontier models and chinese frontier models in the same criminal pipeline. the operator apparently did not care where the model came from. only whether it worked.
the depth is what separates this from a simple script. on one victim the agents chained 13 steps without a human walking them through it. an unauthenticated sql injection for initial access. then reading a one-time passcode in plaintext to bypass multi-factor authentication. into the admin panel. a file upload that turned into code execution on the host. privilege escalation through a sudo misconfiguration. a mount into another system, credentials pulled from a wordpress install, a plugin turned into more code execution, 46 secrets dumped out of aws secrets manager, the magento database opened, the encryption key lifted, and the card data decrypted.
no single one of those steps is novel. a competent human pentester or red teamer does all of it. the point is the agent did all of this work on its own, in the correct sequence. it was capable of reacting to what it found, and acting similar to how a professional would act.
much of our behavioral detection and intelligence tradecraft benefits from repeatability. tools an adversary prefers, infrastructure it reuses, hours it keeps, and ttp's persisting from victim to victim. that is the logic sitting near the top of the pyramid of pain. the closer you get to behavior, the more expensive it becomes for the adversary to change.
an agent choosing its path fresh on every target does not carry those habits the same way. the infrastructure still exists, and the staging server still existed, which is exactly how gambit caught it. but the intrusion itself does not carry a person's fingerprints, because a person was not deciding the steps. the intrusion path was no longer a direct reflection of one human operator's habitual workflow.
i have been writing about this very topic for a quite some time now. first it was agents in a lab doing more than they were told. then agents in the wild stumbling into third-party systems. this is the next stage, and it is the least dramatic and the most serious. no accident. no misalignment. no rogue behavior. a criminal treating ai agents as staff, and getting a 119-site campaign out of one person for under $18,000.
the barrier protecting a lot of these retailers was never their security alone. it was the economics of giving a custom target bespoke attention. traditional mass exploitation works brilliantly when thousands of companies run the same vulnerable software. custom applications are different. historically, spending hours probing one mid-sized retailer for a unique path inside required enough human time and skill to make some targets economically uninteresting.
that barrier is what just moved.
when autonomous offensive labor costs roughly $25 per completed scan, targets that were previously not worth hours of skilled human attention can suddenly make economic sense.
the fear was always that ai would become the attacker. that is not what happened. ai became the workforce. the attacker is the same as he ever was. a person who wants your money and just found a much cheaper way to come and take it.
the attacker stayed human. the workforce became software. and the payroll has transformed from direct deposit salary to paying for tokens instead.