A cybercrime campaign investigated by Gambit Security launched 105 attack projects in five days, compromised at least 27 companies and stole more than 600,000 unexpired card records from two victims.
Estimated cost to the attackers: $12,000 to $18,000.
The campaign ran between 10 and 15 September, and ITWeb Africa asked three cybersecurity and AI specialists what it implies for African payment systems.
What the AI actually did
The significance lies in how much work was automated, says Stanislav Kazanov, head of governance, risk and compliance, cybersecurity and sustainability at Innowise.
One operator used 1,951 AI prompts across 260 sessions to carry out tasks that would previously have required a team of hackers.
That is the cost collapse made specific. Not a projection about what agentic systems might enable, but a count of what one person did in five days.
Why current detection misses it
The architecture of fraud screening is the vulnerability, says Matt Goren, founder of RunOctopus.
“Most screening looks at one merchant’s traffic, and an attack spread thinly across 30 sites can look normal at each one.”
That is not a failure of detection quality. It is a failure of scope. Each merchant’s system is doing its job correctly and seeing nothing unusual, because the unusual thing only exists at the level above.
Alex Ferrer, head of blockchain forensic investigations at Crypto Legal, argues financial institutions need network-level analysis capable of connecting apparently unrelated transactions through shared devices, payment instruments, infrastructure and behaviour.
Small merchants carry the exposure
All three specialists identify smaller merchants as most at risk, since few have dedicated security teams.
Recommended measures:
- Hosted payment pages, so card data never touches the merchant’s own systems
- Multi-factor authentication
- Updated software
- Transaction monitoring
Hosted payment pages are the most consequential of these. A merchant that never handles card data cannot leak it, whatever else goes wrong.
Nobody sees the whole attack
Kazanov calls for closer collaboration between banks, payment companies and security specialists to identify stolen-card activity.
Ferrer puts the structural problem plainly: merchants, processors, banks, telecoms operators and authorities each hold different pieces of the same attack.
Assembling those pieces requires data sharing arrangements that mostly do not exist — and which are harder to build across African markets with differing regulatory regimes than within a single jurisdiction.
What this is, and isn’t
The Gambit campaign is not identified as African. The specialists are assessing exposure rather than reporting attacks on the continent.
What makes the assessment relevant is the direction of the economics. As digital payments expand across African markets, attacks that cost under $20,000 to run and scale across dozens of merchants simultaneously become viable against targets that would previously have been too small to bother with.
Payment-security teams, the specialists argue, will need to look beyond individual transactions toward patterns across the wider ecosystem.





