Back
Three open-source AI agents breached a Fortune 500 firm, a US airline and 25+ orgs
SiTech AI Team2 წთ. საკითხავი

Three open-source AI agents breached a Fortune 500 firm, a US airline and 25+ orgs

A financially motivated operator used three open source AI agents to hit hundreds of online retailers, stealing more than 600,000 credit card records for an average of about $25 per company.

A financially motivated attacker used three open source AI agents to break into hundreds of online retailers, stealing more than 600,000 credit card records and planting card-stealing scripts on checkout pages. AI security firm Gambit Security recovered the operator's server and rebuilt the campaign from its logs and tooling, threat intelligence director Eyal Sela wrote on 22 September.

The victims include a Fortune 500 hospitality company, a major US airline, a large US industrial supplies distributor and a US online fashion retailer. Between 10 and 15 September the operator launched at least 105 attacks and compromised at least 27 companies to varying degrees. The campaign goes back to July 2026 and was still running.

Timeline of the Cairn harness's attack projects

Three agents, one operator

Strix searched for exploitable flaws, running 146 times against 138 hosts between 23 and 31 August. Cairn handled end-to-end exploitation. Hermes orchestrated the campaign through a Chinese-language persona called SOUL - Red Team Operator, with 121 skills, 78 of them attack skills, plus one written to remove the harness's own content filters.

The human typed 1,951 prompts in Chinese across 260 sessions, mostly short instructions such as "see whether the file upload in the report can give code execution". Gambit says the harness ran on Anthropic's Claude Opus 4.6 after newer models refused the requests.

25 dollars a target

Model access went through OpenRouter. A balance captured on 25 August recorded $7,005.71 spent over four weeks, and Gambit estimates the full campaign cost $12,000 to $18,000: a mean of $25.46 for each of 101 completed scans, from $3.13 at the cheapest to $79.31 at the most expensive.

Cards stolen, data destroyed

Where access was achieved it usually took under a day, often a few hours. One documented chain began with an unauthenticated SQL injection and ended with root access, 46 secrets from AWS Secrets Manager and the encryption key of a Magento database.

Skimmers were ordered for at least 27 named victims and confirmed on 19 of them. One operator skill told the agent to wipe card fields after exfiltration, and at a bicycle retailer the cleanup dropped 180 tables matching the agent's staging prefixes, including backups the victim's own administrators had made. Gambit's conclusion: data loss can now arrive as a side effect of someone else's routine.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.