Single operator used three open-source AI harnesses to compromise 27 retailers in five days for $25 per attack

According to Israeli security company Gambit, an attacker used three open-source AI tools—Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes for campaign orchestration—to target 105 online retailers between September 10-15, compromising at least 27 companies and extracting over 600,000 credit card records. The operator spent approximately $7,006 on AI model access via OpenRouter over a five-month period, averaging $25 per successful attack. Access to compromised systems typically took less than a day.

Topics

AI securityAgentic AI

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.