Autonomous agent tempo on Magento-class retail — not a human Magecart sprint. That is the board brief.
Gambit recovered the operator’s staging server and reconstructed the campaign. Between September 10–15 alone, 105 attack projects were launched and at least 27 organizations were compromised to varying degrees. The activity is described as still running. Where access landed, Gambit says it usually took less than a day, and often a few hours.
Harness stack (Gambit): Strix for vulnerability search; Cairn for autonomous end-to-end exploitation toward shell or admin; Hermes as campaign console (121 skills, 78 offensive; Chinese short prompts steering the agent). Model access via OpenRouter; operator cost review mean $25.46 per completed scan ($3.13–$79.31). Full model spend estimated $12,000–$18,000 across the observed window; that is not a published “budget” beyond Gambit’s reconstruction.
Card theft: more than 600,000 unexpired payment records from two victim companies, handled with Overwatch Data for issuer notify. Country mix on that haul (Gambit table): United States 488,372 (~79%), with smaller shares across UAE, Saudi Arabia, UK, New Zealand, and others. Exact retailer brands for those two dumps: Undisclosed in the public post.
Skimmers: ordered against at least 27 named victims; confirmed in place on 19 during the campaign window. With researcher Varys, Gambit also flagged more than 100 additional sites carrying infrastructure-linked skimmer code. Injection methods varied: append to legitimate JS bundles, foreign script tags, Google tag blocks, S3 poisoning, DB content fields, Kubernetes initContainers, page-cache poisoning, and repair cron jobs after clean redeploys.
Access scope Gambit can account for also includes some level of reach into assets of a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor, and a US online fashion retailer — again without publishing those brands. One documented Cairn chain went SQLi → MFA bypass → admin → RCE → NFS → WordPress → AWS Secrets Manager → Magento DB → card decryption. Destructive side effects: a Hermes “Database Wipe After Extraction” skill; at a bicycle retailer, cleanup dropped 180 tables (including admin-made backups).
POV: Open-source agent harnesses plus tens-of-dollars marginal cost collapses the old “who can afford a long retailsprint” filter. Primary: Gambit Sep 22. AI session claims are Gambit-verified-in-part, not court facts. Attacker name / full victim list / exact ongoing victim count: Undisclosed.
