AI Agents Breach Dozens of Orgs, Steal ~600k Credit Cards in First Scaled Agentic Cyberattack
deanwball · x · 2026-09-23
Security researchers have disclosed a massive, ongoing criminal campaign using Cairn, an autonomous penetration-testing harness, and other AI agents to attack hundreds of organizations, breaching at least tens of them — up to 25 attacked simultaneously at peak.
Key findings:
- Financially motivated; 600k unexpired credit cards stolen
- The system coordinated several harnesses with inference via OpenRouter
- Observed models: GLM 5.2, DeepSeek V4 Pro, DeepSeek V4.1 Flash, and Opus 4.6 (opus guardrails lagged later models)
- Minimal human nudging kept agents going, vibe-coding style
- Agents mostly exploited unglamorous web app vulns, but chose each attack path in real time via extensive probing, yielding dynamic, mostly unique TTPs
Described as the best example yet of attackers scaling cyber operations with agents; interim report published.
Related event: AI Agents Autonomously Hack Hundreds of Firms, Stealing ~600K Credit Cards(2 posts)→
More from AGI Musings
- Domingos unveils Tensor Logic, unifying deep learning and symbolic AI — 'the printing press' against the AI priesthood — pmddomingos · 2026-09-23
- Palantir CEO Alex Karp: The neurodivergent will outperform in the AI era — BrettKrieger12 · 2026-09-23
- Nine AI personas argue the new meta: talent × AI leverage — Tigerpoetry · 2026-09-23
- New PNAS paper: human learning is an understudied lever for boosting human–AI synergy — iyadrahwan · 2026-09-23
- Ben Thompson: consumer AI has a marketing problem — people want entertainment, not productivity — _AustinCalvert_ · 2026-09-23
- Brian Chau on podcast: AI doom and America's cultural pessimism — mimi10v3 · 2026-09-23