September 24, 2026

AI Agents Targeted 100 Retailers at $25 a Target. The Victims’ Own Access Did the Work.

Table of contents

The operator behind the card-skimming campaign where AI agents targeted 100 retailers from July into September 2026 kept a cost sheet. A mean of 25.46 dollars per target across 101 completed runs, a floor of 3.13, a ceiling of 79.31. Most coverage quoted those numbers as a novelty. They are a pricing model for AI-powered cyberattacks, and they decide who is worth attacking.

For most of this field's history the scarce input in an attack was a skilled person's time. That cost quietly protected most companies. An operator worth their rate chose targets worth the hours, and a regional retailer stayed safe by being too dull to bill for. That floor is gone.

How AI agents targeted 100 retailers at once in AI-powered cyberattacks

In one of the most notable AI cyberattacks on retailers, the campaign used three open-source agents in sequence. One swept candidate hosts for weaknesses. One took a single target and a blunt goal, get a shell or admin access. One ran the operation and carried a library of attack skills, including one written to strip its own safety filters.

Model choice shifted mid-campaign as newer models refused requests, so the operator fell back to older and alternative ones. The model is a footnote. What changed is throughput. Running known techniques end to end in AI agents cyberattacks against a hundred targets at once now costs the price of API calls enabling a $25 per target cyberattack where between September 10 and 15 the operator launched 105 attempts and kept whatever fell out.

He never judged any single company worth the effort. He judged the batch worth it, demonstrating how AI cyberattacks on retailers allow operators to let the yield rate pick winners. Being unremarkable protects a company only while someone has to look closely enough to find it unremarkable. Nobody looked as AI agents targeted 100 retailers simultaneously.

The intrusion needed one exploit, then valid credentials the whole way

One reconstructed run opened with an injection flaw on a login parameter. After that, the environment paid for every step. A one-time password sat in clear text in a database table, so the admin panel was a login rather than a problem to solve. From that panel the agent uploaded a file with no extension check and ran code as a low-privilege user. A sudo rule that asked for no password promoted it to root. Cloud keys sat within reach of that root, so the card data was a copy operation.

Count what happened. One exploit at the front. Then a plaintext OTP, an admin session, an uploaded shell, a standing sudo rule, and an over-scoped cloud key. Five identities, each already trusted, chained into a clean path to crown jewels. Nobody broke in. They logged in, over and over, with valid credentials in the wrong hands.

Nothing raised an alarm because every step looked normal

Login-time and perimeter controls check identity at the door and step aside for the session. Every action here used real credentials, so no alarm fired because nothing looked wrong. A database read, an admin upload, a cloud call with a working key. Each one reads as an ordinary Tuesday.

Rotation does not reach the root condition in these AI-powered cyberattacks. Rotate the exposed key and one artifact is gone. The readable secret store, the passwordless sudo rule, and the open path from an unauthenticated endpoint to a cloud secret all remain. The exposure is the topology of standing access, and rotating a credential leaves the topology untouched.

Persistence made the gap plain. At one retailer the team shipped a clean site and the theft returned within minutes, because a cron job and the key behind it reinstalled the skimmer. The intrusion artifact was evicted and the access that rebuilt it was never in scope.

One detail belongs in your recovery planning. The agents were told to wipe the card fields after extraction, and at one victim the cleanup dropped tables matching backup names and destroyed the company's own recovery data. An operator who is not paying by the hour has no reason to be careful.

The full chain above comes from a single reconstructed intrusion. Card and victim totals come from analysis of the operator's exposed server, not from the named companies. The operator worked in Chinese and appears financially motivated. Nothing so far ties the campaign to a state.

Three questions your board will ask after this campaign

  • Which identities can reach our payment systems, and how many steps does it take from the public internet? The wrong answer is that the firewall covers it, because this attack never touched the firewall after the first step.‍
  • When the last cloud project wrapped, who still holds the keys and service accounts it created? The wrong answer is that rotation handles it, because rotation changes a secret and not what that secret can reach.‍
  • If one service account is taken tonight, can we show where the access stops? The wrong answer is that the logs will tell us, because you will find out where it stops when an auditor or an attacker does.

How Unosecur changes the outcome

Standing access keeps erasing hard steps during AI cyberattacks on retailers because no team sees it whole. Permissions sit in one console, cloud keys in another, service accounts and AI agents in a third. The path from a login form to a payment database lives only in the union of all three, where nobody is looking.

Unosecur builds that union. It inventories AI agents, non-human identities, and human identities across cloud and SaaS, stitches each entity's scattered accounts into one record, and flags the exact conditions this operator chained. Excess privileges, standing privileged access, persistent access paths, and lateral movement surface ranked by blast radius.

For the retailer above, Unosecur would have drawn the readable secret, the passwordless sudo rule, and the over-scoped key as one path long before an agent walked it, effectively stopping AI-powered cyberattacks before damage occurs. Each finding goes to an owner with the steps, verification, and rollback to close it. The operator's only real edge was reading the victim's identity graph first. Unosecur is how you protect against future AI cyberattacks on retailers before he strikes.

‍

Get a Personalized Demo
Ready to secure your identities?
Get a Personalized Demo
Ready to secure your identities?