AI Governance

27 companies breached for $25 a go: AI agents as attack tooling

Published
Read time3 min read
AI Governance

Between 10 and 15 September 2026 a single operator ran at least 105 attacks and compromised at least 27 organisations, among them a Fortune 500 hospitality company, a major US airline, a large industrial supplies distributor and an online fashion retailer. The work was done by three open-source AI agent frameworks chained together. The operator's own cost review put the mean spend at $25.46 per completed scan.

How the campaign worked

According to research by Gambit, reported by The Register, the operator combined three open-source agent harnesses, each doing a different job:

  • Strix — vulnerability discovery and scanning
  • Cairn — autonomous exploitation, including obtaining shell or administrator access
  • Hermes — the orchestration layer tying the two together

The results included at least 600,000 unexpired credit card details taken from two companies, and card-stealing skimmer scripts installed on the websites of five more. Model access was bought through OpenRouter: $7,005.71 over the first four weeks, after which the operator continued for three more weeks at twice the daily volume. Gambit puts the total campaign cost somewhere between $12,000 and $18,000.

The economics
Mean cost per scan
$25.46 across 101 completed scans.
Cheapest / most expensive
$3.13 and $79.31.
Return
600,000+ card records from two victims, skimmers on five more.

Why the cost figure is the story

Skilled offensive work has always been constrained by the supply of skilled people. That constraint shaped everything about how defenders think: you assumed a serious adversary would target you deliberately, and that opportunistic attackers would run cheap, noisy, easily detected scans.

An agent harness that finds a vulnerability, exploits it and escalates for the price of lunch collapses the distinction. Targeted-quality effort can now be applied indiscriminately. The question "why would anyone bother attacking us?" has a new answer: because bothering costs $25.

Two consequences follow for anyone running internet-facing systems.

Obscurity has stopped working. Being a mid-sized company in an unglamorous sector used to be a real, if unearned, control. If the marginal cost of assessing one more target approaches zero, every target gets assessed.

Time-to-exploit compresses. The window between a vulnerability becoming known and being exploited against you was, historically, a function of attacker attention. Automation removes the queue.

The card data angle

Skimmer scripts on five victims' websites is the same attack pattern behind the recent BigCommerce third-party app compromise — malicious JavaScript on a page that takes payment details. PCI DSS 4.0 tightened requirements around exactly this: maintaining an inventory of every script on payment pages, justifying each one, and detecting unauthorised change.

Those requirements have an implementation cost and it is tempting to treat them as paperwork. Campaigns like this are the argument against that reading. Script integrity monitoring is one of the few controls that would have caught the skimmer stage regardless of how the initial access was obtained.

What to do about it

  • Assume you are in scope. Plan on the basis that everything you expose will be assessed by something, regularly, whether or not anyone has a reason to single you out.
  • Shorten your patch window for external systems. If exploitation is automated, a 30-day SLA on internet-facing assets is a 30-day opportunity.
  • Monitor script integrity on payment and form pages. The initial access varies; the skimmer stage is detectable.
  • Test the way they attack. Automated coverage across the whole external estate, with expert testing on the systems that carry money and sensitive data, is a closer match to this threat than an annual scoped test.

Find out what an automated attacker would reach across your whole external estate.

Explore penetration testing

Common questions

No. Strix, Cairn and Hermes are open-source agent frameworks. The operator chained them so that one handled vulnerability discovery, one handled autonomous exploitation and one orchestrated the workflow. The capability came from the combination rather than from bespoke tooling.

The operator's own cost review recorded a mean of $25.46 per completed scan across 101 scans, ranging from $3.13 to $79.31. Gambit estimates the total campaign cost at between $12,000 and $18,000, including $7,005.71 spent on model access via OpenRouter over the first four weeks.

It changes what you test rather than only how often. If exploitation is cheap and automated across your whole external footprint, continuous automated coverage of that footprint matters more than a once-a-year scoped engagement, with expert testing reserved for the systems carrying money and sensitive data.

Sources

  1. Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs — The Register, 25 September 2026
  2. Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records — Hackread, 25 September 2026