Gambit Security reported a financially motivated campaign in which one Chinese-speaking operator directed three open-source AI-agent tools against online businesses. The tools handled much of the work, but a person still provided instructions. At least 27 companies were compromised to varying degrees, and more than 600,000 payment-card records were stolen from two of them.
3
7
12
Three tools, three roles
The operator used the tools as a connected workflow rather than as one all-purpose agent:
- Strix searched for vulnerabilities.
- Cairn attempted to exploit weaknesses and gain access.
- Hermes coordinated the operation and directed activity across the tools.
2
3
6
This division let the operator delegate parts of the attack process and leave much of the work running unattended. “Largely autonomous,” however, does not mean independent of human input: Gambit’s findings were reported as including 1,951 human prompts across 260 sessions.
6
12
What the reported activity and costs show
Between September 10 and 15, the operator launched 105 attack projects. At least 27 companies were compromised to varying degrees during that period; those figures do not mean every target was breached.
3
12
Reporting puts the average cost at about $25 per completed scan, with one account giving a more precise average of $25.46. That is a cost-per-scan figure, not a confirmed cost for each successful breach.
7
10
Accounts of the underlying AI models are less consistent. Reports mention DeepSeek models and Claude Opus 4.6, but the available coverage does not establish a reliable, complete model-to-tool mapping.
2
6
Stolen card data and skimmers
More than 600,000 payment-card records were reportedly taken from two compromised companies—not from all 27. The campaign also involved skimmer scripts on online stores, which can capture payment details entered during checkout.
7
12
An automated cleanup caused collateral damage
Gambit’s findings also described an agent cleanup routine that destroyed a victim’s database data, including backups, according to reporting on the incident. The episode illustrates a risk of delegating post-compromise tasks to automated systems: an action intended as routine cleanup can affect data beyond what the operator meant to target. The available sources do not establish the full extent of the resulting loss.
4
6
Was the campaign stopped?
The reporting described the campaign as ongoing when Gambit published its findings. The available sources do not establish that it has since been stopped or document the outcome of specific disruption efforts.
7
18