AI news

Malicious AI Agents Are Hitting Online Shops: How to Get Ahead of the Risk

A campaign of autonomous AI agents is stealing payment card data from e-commerce sites. Swiss SMEs with online stores need to rethink their cybersecurity now, not later.

FlowBiz.ai25 September 2026 4 min readBased on Netzwoche

Photo : Netzwoche

Key takeaways

  • Open-source AI agents are automatically attacking online shops to steal payment data
  • Over 600,000 payment cards compromised at two companies according to Gambit's investigation
  • Total campaign costs estimated at just USD 12,000 to 18,000 for hundreds of attacks
Contents
  1. What We Know About This Campaign
  2. What This Means for Your Swiss SME
  3. Hypothetical Scenario: An Artisan Cheese Dairy in Valais
  4. Key Concerns for Swiss SMEs
  5. What to Do Now

Malicious artificial intelligence agents are currently attacking online shops in a near-autonomous manner. According to Netzwoche, an ongoing campaign exploits three open-source tools to detect vulnerabilities, infiltrate systems, and steal payment card data.

For a Swiss SME leader with an online store, this development changes the game. The threat is no longer a lone hacker targeting a large corporation. It is a machine knocking on hundreds of doors in parallel, at low cost, and it is knocking on yours too.

What We Know About This Campaign

Cybersecurity startup Gambit has identified an active campaign running since at least July. Between September 10 and 15 alone, the systems launched 105 attacks and gained access to at least 27 businesses. Two of these saw more than 600,000 payment card numbers stolen.

Three agents share the workload. Strix scans websites for vulnerabilities. Cairn attempts to exploit them to gain administrator rights. Hermes coordinates the operation and makes tactical decisions after a successful intrusion. The human operator provides only brief instructions; the agents execute the rest autonomously.

Methods vary by target: injecting malicious code into legitimate JavaScript files, manipulating payment pages, altering content in cloud storage, or interfering with Kubernetes configurations. In one case, an automated process checked every two minutes that the data-stealing script was still in place and reinstalled it if necessary.

What This Means for Your Swiss SME

This campaign primarily concerns SMEs with a proprietary online shop: WooCommerce, PrestaShop, Magento, or custom-built solutions. If you delegate everything to a major SaaS platform (Shopify, Wix, etc.), the technical risk lies with the provider, but your legal liability in case of a breach remains to be clarified with them.

Your SituationLevel of VigilancePriority Action
E-commerce site managed in-house or by a service providerHighSecurity audit, urgent update
Marketplace or SaaS platformModerateCheck terms of service and liability in case of breach
No online salesLow for this riskWatch other vectors (phishing, ransomware)

The cost of these attacks is particularly alarming. Gambit estimates total campaign expenses between USD 12,000 and 18,000, for hundreds of attacks. A successful intrusion often takes less than a day, sometimes just a few hours. "The barrier to entry is dropping considerably," Gambit concludes.

Hypothetical Scenario: An Artisan Cheese Dairy in Valais

Imagine a cheese dairy in the Broye region that developed an online shop to sell its tommes and raclettes directly to consumers. The site runs on WooCommerce, hosted with a low-cost German provider. Plugin updates have not been done for six months.

An agent like Strix detects a known vulnerability in an outdated version. Cairn exploits it to gain administrator rights. Hermes installs a skimmer on the payment page. Customers enter their card numbers; the data flows to an external server. After the theft, a cleanup routine erases traces, deleting backup tables in the process. The cheese dairy only notices when customers report fraudulent payments.

The damage: loss of trust, complaints to the Swiss nFADP (nLPD), sales interruption in peak season, restoration costs. The incident could hypothetically represent several days of management time and thousands of francs in expenses.

Key Concerns for Swiss SMEs

Hosting and the Swiss nFADP (nLPD). The theft of payment card data triggers mandatory notification to the Federal Data Protection and Information Commissioner (FDPIC) and affected individuals. Hosting in Switzerland does not make you immune to attacks, but it clarifies the legal framework. For an analysis of your situation, consult the FDPIC or a specialist.

Hidden costs. Prevention has a price, but post-incident response has another: technical forensics, regulatory notification, emergency hardening, lost business. Gambit's report notes that an automated cleanup routine deleted 180 data tables, including backups. Recovery then becomes complex.

Tool accessibility. The three agents used are open-source and publicly available. This democratization means the same tool can be used to test your security or to breach it. The line between legitimate penetration testing and malicious attack hinges on authorization, not technology.

Defense maturity. Many Swiss SMEs still underestimate the attack surface of an e-commerce site. An outdated plugin, an exposed API key, a poorly protected administrator account: AI agents scan precisely these details, at scale and relentlessly.

What to Do Now

  1. Take inventory of your e-commerce setup. Which system, which version, which plugins or extensions, where is it hosted, who has administrator access. Note the dates of last updates. If you cannot find this information in under ten minutes, that is already a signal.
  2. Verify your backups. They must be automated, stored off-site, and tested regularly. The case reported by Gambit shows that internal backups can be destroyed by the same attack. An isolated backup is your safety net.
  3. Examine your payment page. If you use a skimmer or redirect, ensure the scripts loaded are the expected ones. Regular visual checks of your browser console on your checkout page help spot anomalies.
  4. Talk to your technical provider. Ask whether they monitor autonomous AI agent campaigns, what their compromise procedure is, and how they handle security updates. If the answer is vague, consider a second opinion.
  5. Test your resilience. FlowBiz.ai offers a two-minute AI quiz to quickly assess your digital maturity. For a deeper analysis of your automations and security, see our AI solutions for SMEs or our automation examples.

Malicious AI agents are not a tomorrow threat. They are active today, at a cost that makes crime profitable and accessible. For a Swiss SME, the question is no longer whether you will be targeted, but whether you will be ready.

Frequently asked questions

My online shop is small, am I really at risk?+

Yes. AI agents automate vulnerability scanning at scale without regard to business size. The campaign documented by Gambit hit hundreds of sites. Your revenue matters less than the presence of an exploitable technical vulnerability.

What is the difference between a malicious AI agent and a classic virus?+

A virus follows a fixed script. An AI agent makes tactical decisions based on what it discovers on your system: it adapts its method, chooses which vulnerability to exploit, and coordinates multiple attack stages. This autonomy makes it harder to detect with traditional tools.

Can I rely on my hosting provider for security?+

Partially. The provider typically manages infrastructure, not your e-commerce application, your plugins, or your administrator passwords. Read the contract carefully to know where their responsibility ends. Security is a shared burden to clarify in writing.

How can I tell if my site is already compromised?+

Watch for unexpected file modifications, unfamiliar scripts in your checkout, traffic spikes to unknown servers, and customer complaints about fraudulent payments. Regular audits by a specialist remain the most reliable way to be certain.

And in your business, what could we automate?

Answer a few questions and get a free, personalised AI pre-diagnosis with three concrete leads in two minutes.

Share this article

Malicious AI Agents Are Hitting Online Shops: How to Get Ahead of the Risk | FlowBiz.ai