Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
The campaign used open source AI tools to automate attacks, and Gambit said two breaches alone exposed more than 600,000 card records.
6 Articles
6 Articles
One Hacker, Three Open-Source AI Agents: How a Low-Cost Operation Breached Airlines, Hotels and Hundreds of Retailers
A Chinese-speaking operator used three open-source AI agents to autonomously breach hundreds of online retailers, stealing over 600,000 credit cards and gaining access to a Fortune 500 hospitality firm and major U.S. airline. The low-cost campaign, running since July 2026, averaged just $25 per target and continues today.
Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs
Operator’s AI bill averaged just $25 per completed scan
A Chinese-speaking hacker used AI models from Anthropic, DeepSeek and Moonshot to steal more than 600,000 credit card data within five days. Tags: #Cyber Crime #hacker attacks up-to-date #Artificial Intelligence
Three Open-Source AI Agents Ran 27+ Breaches for $25 a Target. 600,000+ Cards Followed.
Gambit Security recovered a staging server used to execute the first documented large-scale autonomous AI agent breach campaign. Active since July 2026, the operation compromised at least 27 organizations. The attacker, using the persona SOUL – Red Team Operator, loaded instructions onto an orchestration agent. The system processed 1,951 short Chinese prompts across 260 sessions to maintain the attack tempo. The architecture utilizes a three-age…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










