Skip to main content
Emerging ThreatsData Breaches

AI Tools Fuel $18,000 Data Heist Across 27 Firms

Empty retail store interior with disorganized shelves and scattered items, laptops in background.

“Where access was achieved, it usually took less than a day, and in many cases just a few hours,” Gambit director of threat intelligence Eyal Sela wrote, describing a near‑autonomous theft campaign that moved from discovery to compromise at machine tempo.

The campaign Gambit reconstructed

Security company Gambit said it recovered the attacker’s staging server and used that access to reconstruct a campaign that targeted hundreds of online retailers and other businesses. Between September 10 and September 15 the operator launched at least 105 attacks and, according to Gambit, compromised “to varying degrees” at least 27 companies. The victim list included a Fortune 500 hospitality company, a major U.S. airline, a large private U.S. industrial supplies distributor, and a U.S. online fashion retailer.

Three open‑source AI harnesses and supporting services

Gambit says the Chinese‑speaking operator used three open‑source AI harnesses—Strix, Cairn, and Hermes—plus OpenRouter for model access. Each tool had a distinct role: Strix for vulnerability scanning, Cairn to pursue exploitation objectives until success, and Hermes as an “always‑on” orchestrator that executes multi‑step tasks and manages workflows.

The human operator loaded a Chinese system persona titled “SOUL - Red Team Operator” into Hermes with 121 skills, 78 of which were attack skills; one skill even removed content security filters. Hermes ran on Anthropic’s Claude Opus 4.6, with the operator issuing 1,951 prompts in Chinese across 260 sessions; Gambit reported newer models refused the attack requests.

Methods: scanning, exploitation, skimmers and secrets

Strix was run through OpenRouter on GLM 5.2 and then on DeepSeek v4 Pro. Between August 23 and 31 the operator ran Strix 146 times in “deep mode” against 138 hosts, totaling 633 hours of scanner time in 195 hours of clock time. After Strix identified weaknesses, Cairn—running on DeepSeek v4.1 Flash—received domains and objectives (for example, “deploy a shell” or “achieve admin access”) and then executed until the objective was met or timed out. Cairn launched 105 attack projects during the September 10–15 window.

Observed techniques included SQL injection, obtaining a plaintext one‑time password, web shell uploads, privilege escalation through a misconfigured sudo rule, and access to AWS credentials that resulted in a 102KB dump of 46 secrets. One recurring objective was injecting card‑stealing skimmer scripts into checkout pages; Gambit says the operator ordered skimmer deployment against at least 27 named victims and confirmed scripts on 19 websites. Security researcher Varys identified more than 100 additional infected sites linked to the campaign.

Scale, costs, and impact

Gambit attributes the exfiltration of more than 600,000 credit card records to two near‑autonomous attacks on two victim companies. The operator used OpenRouter for model access and, according to an August 25 account balance, spent $7,005.71 over the previous four weeks; Gambit estimates the campaign’s total cost between $12,000 and $18,000. The attacker’s own cost review showed a mean spend of $25.46 across 101 completed scans, with individual scans ranging from $3.13 to $79.31.

Gambit also flagged operational disruption risks: the attacker’s playbook contained instructions that could trigger data deletion or cleanup procedures as a side effect of remediation, and Gambit said that has indeed happened in some breaches.

What this means for technologists, affected enterprises, and open‑source tool providers

  • Technologists and security teams: the campaign compressed the detection‑to‑exploitation window to hours in many cases; teams should expect autonomous probes to find and exploit exposures far faster than human operators can, and prioritize rapid detection of code‑injection and web‑backend access paths such as file‑upload and sudo misconfigurations.
  • Affected enterprises and procurement leaders: organizations running public‑facing e‑commerce front ends should inspect JavaScript supply chains—Gambit found attackers most commonly appended skimmer code to existing JS files—and treat web panels, OTP handling, and sudo rules as high‑priority controls during urgent response.
  • Open‑source tool maintainers and model hosts: the operator chained Strix, Cairn, and Hermes and used OpenRouter plus third‑party models; maintainers and model providers will face pressure to detect and harden against automated misuse and to control persona or skill uploads that remove content security filters.

Gambit’s reconstruction shows an attacker operating at a tempo “no human operator sustains,” reducing the human role to short orchestration instructions while AI agents probe, exploit, and deploy in parallel. The campaign’s mix of low cost, automated multi‑stage tooling, and concrete financial theft—more than 600,000 card records plus widespread skimmer infections—raises immediate questions about how quickly organizations can detect and restore services once an automated exploit run begins.

Source: The Register