The $25 Attack: Agentic AI Just Made Card Skimming a Volume Business
Meta title: Agentic AI Card Skimming: The New Economics of Payment Fraud | Quantum Payments Meta description: AI agents stole 600,000 card records from 119 retailers for about $25 per target. Here is what agentic fraud attacks mean for payment security, approval rates and merchant fraud strategy. Suggested slug: agentic-ai-card-skimming-payment-fraud
Executive summary
A card-skimming campaign documented by Gambit Security has changed the economics of payment fraud.
Using three open-source AI agents, an attacker targeted hundreds of online retailers, compromised at least 119 websites and stole more than 600,000 card records from just two businesses. In one five-day period, the campaign compromised at least 27 companies and launched more than 100 distinct attacks.
The estimated cost was between US$12,000 and US$18,000 for the full campaign, or approximately US$25 per targeted company.
That figure matters more than the malware itself. It means the attacker no longer needs rare expertise or significant capital to run a mass card-skimming operation. The constraint is now target selection, not capability.
For merchants, the exposed weakness is not only the card. It is the asset-light checkout stack: JavaScript files, third-party tags, CDNs, server-side caches, cloud storage, databases and automated deployment processes.
The response cannot be to block more customers. With 47 per cent of merchants estimating that up to 5 per cent of legitimate orders are wrongly declined, the next phase of payment security must improve signal quality while protecting the payment success rate.
The economics of attack have inverted
The campaign used Strix for scanning and vulnerability discovery, Cairn for autonomous exploitation and Hermes as the orchestration layer. The human operator provided short instructions while the agents performed reconnaissance, exploitation, skimming, exfiltration and cleanup.
According to Gambit, Strix ran 146 times against 138 hosts over nine days, accumulating 633 scanning hours. Cairn was able to pursue objectives such as obtaining shell or administrator access for hours at a time.
The attack methods varied according to the access available. They included malicious code appended to legitimate JavaScript files, script tags inserted into checkout pages, CDN and S3 poisoning, server-side cache manipulation, database changes, Kubernetes deployment alterations and cron jobs that restored the skimmer after removal.
The attacker's own cleanup routine was particularly damaging. In some cases, the agent was instructed to wipe card data from Magento databases after exfiltration. That caused data loss and operational disruption, while potentially destroying evidence that incident responders would normally rely on.
Dimension | Traditional skimming economics | Agentic campaign economics |
Reconnaissance | Manual and time-intensive | Autonomous scanning across many hosts |
Exploitation | Dependent on scarce specialist skill | AI agents pursue objectives for hours |
Human input | Continuous tactical intervention | Short prompts and campaign-level direction |
Persistence | Manually maintained | Automated cron, cache or deployment restoration |
Cost per target | High and selective | Approximately US$25 on average |
Defensive implication | Protect the card environment | Monitor the entire checkout supply chain |
The strategic conclusion is uncomfortable: security controls designed around expensive attackers are now mispriced.

The card is not the only asset under attack
Many merchants still think of card security as a processor or tokenisation issue. Those controls remain essential, but they do not prevent malicious code from capturing payment data before it reaches the processor.
The more vulnerable surface is often the web application surrounding the payment form. A merchant may have 20, 30 or 40 vendor tags operating at checkout, alongside analytics libraries, personalisation tools, chat widgets, advertising pixels and content delivery services.
Each dependency creates a possible path into the customer journey.
A clean payment processor response does not prove that the checkout was clean. A skimmer can sit inside a legitimate JavaScript bundle, hide inside a tag block or arrive through a poisoned cache. If the attacker can restore the code every two minutes with a cron job, removing the visible script once is not remediation.
This is why merchants need independent logging and integrity monitoring across the whole payment path. They should be able to establish what code was served, which version was deployed, what changed and when.
The Gambit findings also introduce a new incident-response assumption: evidence may have been destroyed before the breach was identified. A database can be altered after exfiltration. Backups can be affected by overbroad cleanup commands. A forensic investigation that starts with the production system may therefore be incomplete.
Defence is becoming agentic too
The clearest market signal is that defensive technology is moving in the same direction.
Visa has agreed to acquire behavioural biometrics firm BioCatch for US$2.4 billion in cash. BioCatch monitors more than 3,000 session signals, including keystroke timing, touch gestures, device orientation and whether an AI agent is driving activity.
Visa also completed its acquisition of Featurespace in December 2024 for approximately US$925 million. Featurespace provides real-time transaction scoring.
Together, the acquisitions show where payment security is heading: from analysing the transaction alone to analysing the behaviour and environment that produced it.
This is the same technology appearing on both sides of the checkout. Attackers use agents to probe infrastructure and adapt tactics. Defenders use behavioural models and orchestration to recognise abnormal sessions, account takeover patterns and coordinated fraud.
The objective is not simply to identify a suspicious card. It is to identify suspicious behaviour across the session, device, merchant, account and transaction.
Our analysis of the Know Your Agent trust layer explores the related challenge of distinguishing authorised automation from hostile automation. The same principle now applies to security operations: systems need to know whether activity is legitimate, malicious or simply unfamiliar.
The wrong response is blanket friction
A major breach often produces a predictable reaction. Merchants tighten rules, add more authentication and block more transactions.
That may reduce observed fraud, but it can also reduce legitimate revenue.
The PYMNTS Intelligence and Spreedly fraud orchestration report found that 85 per cent of merchants see preventing fraud without degrading customer experience as their biggest challenge. Forty-seven per cent estimate that up to 5 per cent of legitimate orders are wrongly declined.
At the same time, 51 per cent expect fraud-management staffing spend to remain flat or decline, while 63 per cent plan to increase fraud-technology investment. This is an operating model shift: merchants expect technology to absorb more complexity without adding equivalent headcount.
The answer is fraud orchestration. Rather than stacking disconnected point tools, merchants need a decision layer that combines device intelligence, behavioural biometrics, transaction scoring, token status, authentication outcomes, merchant history and payment routing.
Read the $231 billion approval problem for the broader commercial case. Payment security must protect both fraud loss and payment success rate.
Merchant checklist
The margin impact is arriving at the same time
Fraud losses are becoming harder to pass through to customers.
From 1 October 2026, the RBA surcharge ban environment means Australian merchants will no longer be able to add card surcharges on covered card transactions. Fraud, chargebacks and false declines will therefore land more directly on margin.
That makes accurate payment decisioning a commercial requirement, not only a security requirement.
Quantum Payments’ unified payments platform is designed to connect payment orchestration, online and in-person acceptance, tokenisation, business intelligence and operational controls. The objective is to automate the path from checkout through reconciliation without treating fraud, authorisation and finance as separate problems.
What this means for merchants
The $25 attack does not mean every retailer will be breached for $25. It means the economics now support volume.
Attackers can scan more targets, try more intrusion paths and accept lower returns per compromise. A merchant that was previously too small to attract sustained manual attention may now be a viable target for an autonomous campaign.
The defensive response should be equally strategic.
Protect the checkout supply chain, not just the payment credential. Build independent evidence. Use tokenisation. Detect behaviour as well as transactions. Measure payment success rate alongside fraud loss. Most importantly, connect the signals in one decision layer so that a security response does not create a second commercial failure through unnecessary declines.
Agentic AI has made card skimming a volume business. Merchants now need payment security that can operate at volume too.
Authoritative sources
.png)