Download Privacy Needle App

Type to search

Cybersecurity

AI-Driven Attacks Compromise 27 Retailers for $25 per Target

Share

An attacker has used a suite of open-source artificial intelligence (AI) tools to compromise 27 online retailers, with the cost of each successful breach averaging just $25.

Research conducted by the Israeli security firm Gambit revealed that the campaign targeted 105 retailers over a five-day period. The attacker utilised OpenRouter to access various AI models, significantly reducing the manual effort required to identify and exploit vulnerabilities.

Automated Exploitation via AI Harnesses

Gambit identified three specific open-source AI harnesses used to orchestrate the campaign. The attacker employed Strix to search for vulnerabilities, Cairn to conduct autonomous end-to-end exploitation, and Hermes to manage the overall campaign orchestration.

The automation allowed for highly efficient incursions, with most successful accesses taking only a few hours to complete. Financial records captured on 25 August indicated that the attacker spent a total of $7,005 over a four-week period. Costs per target ranged from as little as $3.13 to $79.31.

Significant Data Theft and Skimming

The scale of the theft was substantial. The automated attacks resulted in the theft of 600,000 active credit card details from two targeted businesses. Furthermore, card skimmer scripts were successfully installed at five additional retailers, and an unspecified number of major companies experienced some level of unauthorised access.

Gambit warned that the intensity and sophistication of these attacks signal a shift in cybercriminal activities. The use of AI provides a level of scale and speed that would be difficult for human actors to achieve manually, potentially leading to an increase in automated incursions against large-scale businesses.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.