返回新聞
安全性AI Understanding 簡報

Open-source AI agents breach 27 companies, steal 600,000 credit cards

Gambit Security researchers identified a campaign using open-source AI harnesses to automate attacks on retailers, resulting in the theft of over 600,000 credit card records and significant data destruction.

4 min readRead the linked source
Source-provided image accompanying Open-source AI agents breach 27 companies, steal 600,000 credit cards
來源參考來源記錄
出版商
hackread.com
來源連結
hackread.comhttps://hackread.com/open-source-ai-agents-breach-credit-card-records/
來源類型
連結來源-主要來源狀態尚未確定。
背景60 秒內了解這一點

從這裡開始

測試一下自己AI 代理測驗

發生了什麼事

Gambit Security disclosed a cyberattack campaign running since July 2026 that utilized three open-source AI harnesses—Strix, Cairn, and Hermes—to autonomously breach at least 27 companies. The attackers exfiltrated over 600,000 unexpired credit card records and deployed malicious skimmers on 19 confirmed websites, with over 100 additional sites identified as infected.

Gambit Security researchers recovered an exposed staging server that revealed an ongoing campaign active since July 2026. The operation relied on three open-source AI harnesses: Strix for vulnerability discovery, Cairn for autonomous penetration testing, and Hermes for central orchestration. The attacker’s own records indicated an average cost of $25.46 per scan across 101 completed scans, with individual target costs ranging from $3.13 to $79.31.

Between September 10 and 15, 2026, the operator initiated 105 attack projects, compromising at least 27 companies. Targets included an online fashion retailer, a Fortune 500 hospitality company, a major US airline, and a large US industrial supplies distributor. Human input was sparse; across 260 Hermes sessions, the operator typed only 1,951 short commands in Chinese, often instructing the agent to review reports or continue after gaining access.

The campaign resulted in the exfiltration of more than 600,000 unexpired credit card records from two companies. Malicious skimmer scripts were confirmed on 19 websites, with over 100 additional sites identified as infected. Deployment methods included appending malicious code to legitimate JavaScript libraries, poisoning AWS S3 content, and modifying database content. At one US wine retailer, a cron job restored malicious code every two minutes to maintain persistence.

The attacks also caused significant data destruction. A Hermes skill titled 'Database Wipe After Extraction' instructed the agent to clear payment data from Magento databases after exfiltration. At a bicycle retailer, an automated cleanup routine dropped 180 tables, including backup tables created by the victim’s administrators. Gambit Security worked with the Shadowserver Foundation to notify affected organizations and take down related infrastructure.

來源詳情: hackread.com

為什麼這很重要

This incident demonstrates that open-source AI agents can now execute complex, multi-stage cyberattacks with minimal human intervention and at extremely low cost. The ability of these tools to perform reconnaissance, exploitation, persistence, and data theft autonomously significantly lowers the barrier to entry for financially motivated threat actors, creating a 'remediation clock' that many organizations cannot manage.

The incident highlights a critical shift in cyber threat landscapes where open-source AI agents can perform end-to-end attacks with minimal human direction. The low cost and speed of these attacks, with successful intrusions often taking less than one day, create a remediation challenge for organizations that rely on traditional, slower security response cycles.

The use of specific open-source tools like Strix, Cairn, and Hermes demonstrates that the necessary components for sophisticated automated attacks are now widely available. This reduces the technical barrier for financially motivated actors, potentially leading to a surge in similar campaigns against online retailers and other web-based services.

The destructive nature of the attacks, including the deliberate wiping of databases and backups, indicates that these AI agents are not just capable of data theft but also of causing operational disruption. This dual capability of theft and destruction increases the potential impact on victims and raises the stakes for security teams.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Agents Quiz

What most distinguishes an AI agent from a basic chatbot?

接下來看什麼

Monitor for further disclosures regarding the specific vulnerabilities exploited by the Strix and Cairn tools, as well as industry responses to the deployment of AI-driven skimmers. Watch for regulatory or security framework updates addressing the use of autonomous AI agents in offensive security operations.

Security teams should monitor for signs of AI-driven skimmer deployments, particularly in checkout pages and JavaScript libraries, and ensure that their incident response plans account for rapid, automated attacks.

Developers and security researchers should track the evolution of open-source AI harnesses like Strix, Cairn, and Hermes, as well as any new tools that may emerge with similar capabilities for autonomous penetration testing and exploitation.

Regulators and industry bodies may issue new guidelines or standards regarding the use of AI in offensive security, particularly in response to incidents involving large-scale data theft and destruction by autonomous agents.

相關指引和測驗

人工智慧代理AI 倫理人工智慧安全測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語
覺得有用嗎?