What is confirmed
In its 22 September report, Gambit Security describes a financially motivated operator using three open-source tools: Strix for vulnerability discovery, Cairn for exploitation and Hermes for orchestration. Between 10 and 15 September it observed 105 projects and at least 27 organisations compromised to varying degrees.
Gambit reports recovering more than 600,000 unexpired card records from two companies. It separately describes skimmers on storefronts and other suspected sites; these measures do not prove every targeted store lost card data.
What it means
Researchers describe one chain involving SQL injection, access to a plaintext OTP, a web shell and access to AWS secrets and Magento databases. This is an observed example, not an identical attack path on every site.
A skimmer on a checkout page intercepts data entered before normal submission. A known HTTPS site can therefore be compromised; a reputation scan alone cannot prove malicious code is absent.
What to do
Consumers: check merchant details and official alerts, enable payment notifications and monitor bank activity. Contact your bank to block the card if you see suspicious charges.
Merchants: monitor checkout scripts and third-party assets, revoke unnecessary access, review logs and patch CMS components. If compromise is suspected, engage your incident-response team.
Before entering your card details, review the store for signs of fraud. This check cannot certify that a checkout page is free of skimmers.


