Cheap AI Tools Used to Breach 27+ Companies, Steal 600,000 Card Records
Security firm Gambit has uncovered a campaign in which a Chinese-speaking attacker used three open source AI "harnesses" called Strix, Cairn, and Hermes to break into online retailers and other businesses. By recovering the operator's staging server, researchers reconstructed a campaign that, between 10 and 15 September, launched at least 105 attacks and compromised at least 27 organisations, stealing more than 600,000 credit card records and installing card-skimming code.
Access was often gained in under a day, sometimes within hours. Hermes acted as the orchestrator, running largely on its own to complete multi-step tasks and even write its own attack routines. The operator loaded it with a custom persona containing 121 "skills," 78 of which were designed for offensive use, including one that stripped away the tool's built-in safety filters.
Despite the scale of the damage, the financial cost to the attacker was minimal. Billing records show spending of over $7,000 across four weeks before the pace of attacks doubled, with Gambit estimating total campaign costs between $12,000 and $18,000. The operator's own records show an average of just $25.46 per completed scan, with the cheapest costing only $3.13. Some breaches also triggered accidental data deletion as the AI agents ran cleanup routines.