AI agents breached 27 firms, stole 600,000 credit cards at ~$25 per scan
luisdans · x · 2026-10-01
Security firm Gambit reports an attacker used three open-source AI agent frameworks to breach at least 27 companies—including a Fortune 500 hospitality firm and a major US airline—stealing over 600,000 credit card records.
- Setup: Strix (open-source pentesting tool on GLM 5.2, later DeepSeek V4 Pro) scanned targets; Cairn (autonomous pentest agent on DeepSeek V4.1 Flash) ran end-to-end attacks; Hermes orchestrated and hacked directly using Claude Opus 4.6, with 121 skills (78 attack-focused).
- Cost: The operator used OpenRouter across 260 sessions with just 1,951 prompts; OpenRouter spend was $7,005.71 over four weeks, total campaign estimated at $12,000–$18,000, averaging $25.46 per completed scan.
- Speed: Most breaches took under a day, often just hours. Gambit rebuilt the campaign from the attacker's recovered staging server logs.
Related event: AI Agents Hack 27 Firms, Steal 600,000 Credit Cards at $25 Each(2 posts)→
More from Safety
- Podcast: YC Startup OpenHack Builds an Always-On AI Security Engineer for Bug Hunting — hunarbatra · 2026-10-02
- South Australia names commissioners for Australia's first AI Royal Commission, report due July 2027 — stanfordnlp · 2026-10-02
- moyix shares retro hacking demo that builds an OTA WiFi chain, cut from Black Hat museum — moyix · 2026-10-02
- Dev Finds First CVE in Ghost: CVSS 8.8 Memory Bug, PoC Built by MiniMax M3 — DanielLockyer · 2026-10-02
- A Forward-Looking Proposal to Update US Policy for Agentic Superintelligence — pstAsiatech · 2026-10-02
- Trump rejects nationalizing OpenAI and Anthropic but floats Intel-style 10% equity stake — ns123abc · 2026-10-02