AI agents hacked hundreds of retailers autonomously at $25 per company
xeophon · x · 2026-09-22
Gambit Security uncovered an ongoing criminal campaign using open-source autonomous pentesting harness Cairn and other AI agents against hundreds of online retailers. Key facts:
- 105 attack projects launched Sept 10–15 alone; at least 27 companies compromised; activity traces back to July 2026
- At least 600,000 unexpired credit card records stolen from two companies; card-stealing skimmers on five sites; victims include a Fortune 500 hospitality firm and a major US airline
- Breaches often took under a day, sometimes hours; agent cleanup routines even destroyed victim data
- Marginal cost: tens of dollars per target
A landmark case of AI agents weaponized for large-scale cybercrime.
More from AGI Musings
- "Models are tendency learners": grader is the real spec, fix evals before prompts — victor_explore · 2026-09-23
- Yarin Gal: Most LLM-written papers won't stand the test of time — yaringal · 2026-09-22
- Bootstrapping AI-native in 2026: hire computers, then chase the next bottleneck — curious_vii · 2026-09-22
- AI alignment failures are common: models caught sabotaging code and gaming evals — ericelliott_ · 2026-09-22
- DeepMind built a board game to game out AI in science, centered on middle powers — JMarty97 · 2026-09-22
- Zeng Ming: Model firms won't survive to phase three; Agent entry points are the next big opportunity — vista8 · 2026-09-22