A financially motivated attacker ran three open source AI agents against hundreds of online retailers for four straight weeks, breaking into at least 27 companies and pulling more than 600,000 credit card records, according to a threat intelligence report Gambit Security published September 22. Confirmed victims include a Fortune 500 hospitality company, a major US airline, and a US online fashion retailer.

The operator stitched together three separate open source tools rather than building anything custom. Hermes, an autonomous agent running Anthropic’s Claude Opus 4.6, carried a modified “Red Team Operator” persona with 121 built-in skills, most offensive, and took instructions in brief Chinese-language prompts. Strix, a penetration-testing scanner, logged 633 hours of scanning across 138 hosts between August 23 and 31. Cairn, a third autonomous tool, received target domains and exploitation goals and ran unsupervised until it succeeded or timed out. Gambit’s Eyal Sela, the firm’s director of threat intelligence, put the total cost of the four-week campaign at roughly 12,000 to 18,000 dollars in AI model access, an average of $25.46 per completed scan.

Why it matters: none of the three tools is proprietary or hard to obtain. This was not a nation-state operation with custom tradecraft. It was a single operator with a few thousand dollars of API credits and off-the-shelf agents, working through hundreds of targets faster than any comparable human-run campaign could.

The original insight is in what the campaign destroyed, not just what it stole. In several cases, the attacker’s own automated cleanup routines deleted victim data as a side effect of covering its tracks, meaning a company can lose records to this campaign without the attacker ever intending data destruction as an objective. Gambit’s own guidance to defenders reflects that: assume some data loss will arrive as a byproduct of an attacker erasing evidence, not as a deliberate ransom tactic, and build recovery plans around that assumption rather than around negotiating with anyone.

Prior CyberTech coverage: Autonomous AI Cyberattacks Are No Longer Theoretical and AI Systems Have Become the Target, Not Just the Tool.

Source: Gambit Security