Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
A financially motivated threat actor has been using three open-source AI harnesses (tools that coordinate and run AI tasks autonomously) to conduct low-cost, automated attacks against companies, particularly online retailers.
In its research shared with Hackread.com, Gambit Security researchers recovered an exposed staging server that revealed an ongoing campaign running since July 2026.
BookSecurity Audits
The attacker’s own review calculated an average cost of $25.46 across 101 completed scans, ranging from $3.13 to $79.31 per target, with the tools used to steal payment details and compromise web applications.
Between September 10 and 15, the operator initiated 105 attack projects and compromised at least 27 companies to varying degrees. Identified targets included an online fashion retailer, a Fortune 500 hospitality company, a major US airline, and a large US industrial supplies distributor.
Multi-Stage Exploitation Pipeline
The operation relied on three open-source AI harnesses working together with minimal manual input, including Strix,...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE