Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

forbes+1qz+1qz+1A Chinese-speaking hacker spent roughly $8,000 on AI model access to launch autonomous cyberattacks against as many as 100 online retailers earlier this month, stealing more than 600,000 credit card records in what one researcher called one of "the most severe abuses of AI for exploitation seen so far."qz+1
The campaign, uncovered by Israeli cybersecurity firm Gambit Security, came to light after the attacker accidentally left the server infrastructure used in the attacks exposed on the open web, revealing stolen data, AI tooling, and the prompts used during the intrusions, Forbes reported on Tuesday.qz
Three off-the-shelf, open-source AI orchestration frameworks — Strix, Cairn, and Hermes — formed the backbone of the operation. Strix handled vulnerability scanning, Cairn ran end-to-end exploitation until it achieved a shell or admin access, and Hermes orchestrated the campaign and provided tactical guidance. The AI models powering the agents included Chinese systems DeepSeek and Kimi alongside Claude Opus 4.6, an older version of Anthropic's frontier model. Attempts to use newer Claude releases were rejected, a sign that more recent Anthropic models carry guardrails capable of blocking overt criminal use.cybersecuritynews+2
The human role was minimal. Across 260 Hermes sessions, the operator typed only 1,951 commands, mostly brief phrases in Chinese such as "read the vulnerability report and start." The per-target cost averaged $25.46 across 101 completed scans, ranging from $3.13 to $79.31.qz+1
Between September 10 and 15, at least 27 companies were compromised to varying degrees, with victims including a Fortune 500 hospitality firm, a major U.S. airline, a large industrial supplies distributor, and an online fashion retailer. Skimmers were confirmed on 19 named victims and linked to more than 100 additional compromised sites. Of the 600,000-plus stolen card records, approximately 488,000 belonged to American cardholders. Anti-fraud firm Overwatch Data validated the records as unique and legitimate, and a payment processor found that at least 60 percent of a sampled batch had not previously been flagged for fraud.cybersecuritynews+2
In at least two cases, the agents' cleanup routines went further than intended and wiped victims' own data, including backup tables.qz+1
Anthropic confirmed it identified and banned the account associated with the attacks. Gambit said it has been notifying affected companies and working with Cloudflare and the Shadowserver Foundation to dismantle the hacker's infrastructure, though the attacker has repeatedly rebuilt servers and the campaign continues.gambit+1
"The human being is directing almost fully autonomous AI models, which are strong enough by now to do very sophisticated cyberattacks quickly with close to zero preparation and very high rate of success," said Eyal Sela, Gambit's director of threat intelligence.forbes+1