New Research from Gambit Security Reveals AI Agents Hacking Hundreds of Online Retailers for $25 a Company

Gambit Security’s threat intelligence team today released new research showing how a financially motivated operator used three open-source AI agents to breach online retailers for about $25 each.

Between September 10-15th alone, the operator launched 105 attack projects and compromised at least 27 companies, part of a campaign running since July that is still active. Targets extended to a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor, and a US online fashion retailer.

Some highlights of the research include:

  • Near-zero marginal cost: the operator spent a mean of $25.46 per completed target, from $3.13 for the cheapest to $79.31 for the most expensive, across 101 scans.
  • The human barely showed up: Hermes, the AI orchestration harness, ran 260 sessions on just 1,951 typed prompts. Most were only a handful of words in Chinese, telling the agent to check a report, test a login, or move to the next target.
  • Confirmed credit card theft at scale: more than 600,000 unexpired credit card records taken from two companies, plus skimmer scripts confirmed live on 19 checkout pages and over 100 more sites flagged by outside researchers.

You can find the report here.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading