Skip to content
AI-Driven Hacking Campaign Compromises 600,000 Credit Cards

AI-Driven Hacking Campaign Compromises 600,000 Credit Cards

First seen 25 Sep 2026, 22:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 23:27 UTC
  • •Over 600,000 credit card records compromised from two companies.
  • •Attackers used open-source AI tools, costing an average of $25 per target.
  • •Payment-skimming malware was installed on at least five affected retailers.

A hacking campaign utilizing open-source AI tools has compromised over 600,000 credit card records from two online retailers. Research by Gambit Security indicates that the attackers executed 101 scans across 105 online retailers, with 27 successful breaches occurring over five days. The average cost per attack was approximately $25, with individual costs ranging from $3.13 to $79.31. Payment-skimming malware was found on five of the breached sites, indicating ongoing data theft. The campaign is financially motivated, focusing on volume rather than stealth. Gambit Security has contacted the affected companies, and the attacks have been linked to Chinese-speaking operators. The campaign highlights the increasing sophistication of cybercriminal activities due to AI technologies.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
Gambit Security report published
Gambit Security released findings on a hacking campaign that compromised credit card data from online retailers.
Shattered
2026-09-22
CVE-2026-87902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-25
CISA KEV addition
CISA added CVE-2026-87902 to its KEV catalog, indicating active exploitation.
Shattered
2026-09-25
Multiple outlets report on attacks
The story gained traction across various cybersecurity news platforms, highlighting the scale and impact of the attacks.
Computerworld

More articles in this cluster (4)

Following this threat?

Track Hermes and CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed