Investigators say a financially motivated, Chinese speaking actor used AI agent tooling to launch 105 retail attack projects from September 10 to 15, compromising at least 27 companies; the reported lesson is scalable... The campaign reportedly cost roughly $8,000 in model access, used DeepSeek, Kimi and an older Cl...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How did a Chinese-speaking hacker reportedly use about $8,000 of AI-model access and the open-source agent frameworks Strix, Cairn, and Herm. Article summary: The reported campaign illustrates AI agents being used as an inexpensive, largely unattended intrusion pipeline—not evidence that the models acted independently of an operator. Public reporting attributes it to a Chinese. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
A reported retail cybercrime campaign shows how an operator can combine several AI models with open-source agent frameworks to automate much of an intrusion pipeline. The key point is not that a model independently chose to attack businesses. Rather, an operator reportedly configured and directed agent systems that could run reconnaissance, exploitation attempts, payment-data collection and cleanup at scale. 8
Gambit Security said a financially motivated actor had been using three open-source AI harnesses—Strix, Cairn and Hermes—against online retailers with limited supervision. The activity reportedly began in July 2026 and was continuing when the research was published. 8
During the five days from September 10 through September 15, Gambit reported that 105 attack projects were launched and that at least 27 companies were compromised to varying degrees. 8 Separate reporting described the broader targeting scope as up to 100 organizations and put the model-access cost at about $8,000.
7
The actor was described as Chinese-speaking. That wording reflects investigators’ observations of language and operational artifacts; it does not, by itself, establish the operator’s identity, nationality or any connection to a government.
Reporting connected the campaign to DeepSeek and Kimi models, as well as an older Claude model, working through Strix, Cairn and Hermes. 7
13 The frameworks were reportedly assigned different roles in an automated workflow rather than functioning as a single all-purpose tool.
At a high level, the reported process was:
This is significant because automation can reduce the human time required to repeat a malicious workflow across many targets. Gambit characterized the marginal cost as tens of dollars per company, while reporting on the five-day burst described an overall spend of about $8,000. Those figures are estimates from the investigation, not a universal cost of attacking a business. 7
8
The reported impact was serious but still incomplete in public disclosures. Gambit said more than 600,000 payment-card records had been taken and that checkout-page skimmers had been placed on dozens of pages. 8
19
Forbes reported that the actor gained access to at least 30 websites during the September 10–15 period, while the number of successful breaches among all targeted organizations remained unclear. 7 Other coverage said U.S. cardholders represented a large share of the stolen records.
6
A complete, independently confirmed roster of affected companies has not been publicly established in the material available here. That distinction matters: a target list, a compromised site, a checkout page with a skimmer and a confirmed data-loss disclosure are not interchangeable measures of impact.
According to coverage of Gambit’s investigation, the actor exposed infrastructure used in the campaign to the public internet. That gave researchers access to artifacts that reportedly included the agent setup and data associated with the operation. 13
Those artifacts enabled researchers to reconstruct parts of the campaign and link them to compromised retailers, checkout skimmers and repositories of stolen card data. The figure of more than 600,000 records should therefore be understood as an investigator-reported count from the exposed criminal environment—not as a record-by-record confirmation issued by every affected merchant. 8
13
Reporting said an older Claude version was part of the stack, while newer Claude versions reportedly refused explicitly malicious requests. 7 That is consistent with the purpose of improved model safety controls: to reject requests for harmful cyber activity.
However, the public material does not provide a controlled technical comparison of the relevant model versions, the full prompts, or the surrounding agent configuration. It would be too strong to conclude that one model was inherently responsible for the campaign or that later refusals alone explain the difference. The decisive factor was the operator’s design of the tooling, access and workflow.
Gambit said the campaign was ongoing and that the actor was rebuilding infrastructure. 8 The company’s research provides the main public account of the campaign’s scale and methods. Shadowserver, meanwhile, distributes tailored remediation reports to vetted network owners, governments and national CSIRT partners—a channel that can help move verified compromise intelligence to organizations able to remediate it.
18
For retailers, the immediate takeaway is practical: checkout pages, third-party scripts, exposed administrative surfaces and recovery processes all need continuous attention. The reported data wipes are a reminder that incident preparedness must cover restoration as well as detection. Monitoring for unauthorized changes to payment flows and maintaining tested, isolated backups are especially important when attackers can automate reconnaissance and repeated attempts across many sites.
The larger shift is economic. AI agents can make repetitive offensive tasks cheaper and faster, but they do not remove the need for an operator, infrastructure, access paths or defensive opportunities. The response is equally operational: reduce exposed attack surface, detect changes quickly, verify recovery capability and share validated indicators with trusted responders. 8
18
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Investigators say a financially motivated, Chinese speaking actor used AI agent tooling to launch 105 retail attack projects from September 10 to 15, compromising at least 27 companies; the reported lesson is scalable...
Investigators say a financially motivated, Chinese speaking actor used AI agent tooling to launch 105 retail attack projects from September 10 to 15, compromising at least 27 companies; the reported lesson is scalable... The campaign reportedly cost roughly $8,000 in model access, used DeepSeek, Kimi and an older Claude model, and resulted in more than 600,000 stolen payment card records.
The publicly reported victim list remains incomplete, and “Chinese speaking” is an operational description—not verified nationality, identity or state attribution.