Single operator used three open-source AI harnesses to compromise 27 retailers in five days for $25 per attack A single operator used three open-source AI tools — Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes for campaign orchestration — to target 105 online retailers between September 10-15, compromising at least 27 companies and extracting more than 600,000 credit card records, according to Israeli security company Gambit. The operator spent roughly $7,006 on AI model access through OpenRouter over a five-month period, averaging $25 per successful attack, with access to compromised systems typically taking less than a day. Single operator used three open-source AI harnesses to compromise 27 retailers in five days for $25 per attack According to Israeli security company Gambit, an attacker used three open-source AI tools—Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes for campaign orchestration—to target 105 online retailers between September 10-15, compromising at least 27 companies and extracting over 600,000 credit card records. The operator spent approximately $7,006 on AI model access via OpenRouter over a five-month period, averaging $25 per successful attack. Access to compromised systems typically took less than a day. Topics Sources - Press Read article https://www.csoonline.com/article/4226861/ai-tools-help-hacker-break-in-for-25-per-target.html - Press Read article https://www.theregister.com/security/2026/09/25/crook-used-three-open-source-agents-to-break-into-a-fortune-500-hospitality-company-a-major-us-airline-and-25-other-orgs/5299012 Go deeper This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.