Malicious artificial intelligence agents are currently attacking online shops in a near-autonomous manner. According to Netzwoche, an ongoing campaign exploits three open-source tools to detect vulnerabilities, infiltrate systems, and steal payment card data.
For a Swiss SME leader with an online store, this development changes the game. The threat is no longer a lone hacker targeting a large corporation. It is a machine knocking on hundreds of doors in parallel, at low cost, and it is knocking on yours too.
What We Know About This Campaign
Cybersecurity startup Gambit has identified an active campaign running since at least July. Between September 10 and 15 alone, the systems launched 105 attacks and gained access to at least 27 businesses. Two of these saw more than 600,000 payment card numbers stolen.
Three agents share the workload. Strix scans websites for vulnerabilities. Cairn attempts to exploit them to gain administrator rights. Hermes coordinates the operation and makes tactical decisions after a successful intrusion. The human operator provides only brief instructions; the agents execute the rest autonomously.
Methods vary by target: injecting malicious code into legitimate JavaScript files, manipulating payment pages, altering content in cloud storage, or interfering with Kubernetes configurations. In one case, an automated process checked every two minutes that the data-stealing script was still in place and reinstalled it if necessary.
What This Means for Your Swiss SME
This campaign primarily concerns SMEs with a proprietary online shop: WooCommerce, PrestaShop, Magento, or custom-built solutions. If you delegate everything to a major SaaS platform (Shopify, Wix, etc.), the technical risk lies with the provider, but your legal liability in case of a breach remains to be clarified with them.
| Your Situation | Level of Vigilance | Priority Action |
|---|---|---|
| E-commerce site managed in-house or by a service provider | High | Security audit, urgent update |
| Marketplace or SaaS platform | Moderate | Check terms of service and liability in case of breach |
| No online sales | Low for this risk | Watch other vectors (phishing, ransomware) |
The cost of these attacks is particularly alarming. Gambit estimates total campaign expenses between USD 12,000 and 18,000, for hundreds of attacks. A successful intrusion often takes less than a day, sometimes just a few hours. "The barrier to entry is dropping considerably," Gambit concludes.
Hypothetical Scenario: An Artisan Cheese Dairy in Valais
Imagine a cheese dairy in the Broye region that developed an online shop to sell its tommes and raclettes directly to consumers. The site runs on WooCommerce, hosted with a low-cost German provider. Plugin updates have not been done for six months.
An agent like Strix detects a known vulnerability in an outdated version. Cairn exploits it to gain administrator rights. Hermes installs a skimmer on the payment page. Customers enter their card numbers; the data flows to an external server. After the theft, a cleanup routine erases traces, deleting backup tables in the process. The cheese dairy only notices when customers report fraudulent payments.
The damage: loss of trust, complaints to the Swiss nFADP (nLPD), sales interruption in peak season, restoration costs. The incident could hypothetically represent several days of management time and thousands of francs in expenses.
Key Concerns for Swiss SMEs
Hosting and the Swiss nFADP (nLPD). The theft of payment card data triggers mandatory notification to the Federal Data Protection and Information Commissioner (FDPIC) and affected individuals. Hosting in Switzerland does not make you immune to attacks, but it clarifies the legal framework. For an analysis of your situation, consult the FDPIC or a specialist.
Hidden costs. Prevention has a price, but post-incident response has another: technical forensics, regulatory notification, emergency hardening, lost business. Gambit's report notes that an automated cleanup routine deleted 180 data tables, including backups. Recovery then becomes complex.
Tool accessibility. The three agents used are open-source and publicly available. This democratization means the same tool can be used to test your security or to breach it. The line between legitimate penetration testing and malicious attack hinges on authorization, not technology.
Defense maturity. Many Swiss SMEs still underestimate the attack surface of an e-commerce site. An outdated plugin, an exposed API key, a poorly protected administrator account: AI agents scan precisely these details, at scale and relentlessly.
What to Do Now
- Take inventory of your e-commerce setup. Which system, which version, which plugins or extensions, where is it hosted, who has administrator access. Note the dates of last updates. If you cannot find this information in under ten minutes, that is already a signal.
- Verify your backups. They must be automated, stored off-site, and tested regularly. The case reported by Gambit shows that internal backups can be destroyed by the same attack. An isolated backup is your safety net.
- Examine your payment page. If you use a skimmer or redirect, ensure the scripts loaded are the expected ones. Regular visual checks of your browser console on your checkout page help spot anomalies.
- Talk to your technical provider. Ask whether they monitor autonomous AI agent campaigns, what their compromise procedure is, and how they handle security updates. If the answer is vague, consider a second opinion.
- Test your resilience. FlowBiz.ai offers a two-minute AI quiz to quickly assess your digital maturity. For a deeper analysis of your automations and security, see our AI solutions for SMEs or our automation examples.
Malicious AI agents are not a tomorrow threat. They are active today, at a cost that makes crime profitable and accessible. For a Swiss SME, the question is no longer whether you will be targeted, but whether you will be ready.



