Autonomous AI Agents Are Breaking into Online Retailers (gambit.security)

🤖 AI Summary
A financially motivated threat actor is leveraging open source AI tools to autonomously conduct cyberattacks against hundreds of online retailers, resulting in the theft of over 600,000 credit card records. This extensive campaign, operational since July 2026, saw a surge of activity with 105 attack projects executed in just five days, leading to successful breaches in at least 27 companies, including prominent airlines and hospitality firms. The threat actor utilized three autonomous AI systems—Strix for vulnerability scanning, Cairn for exploitation, and Hermes for orchestration—allowing for rapid and efficient attacks costing only a few dollars per target. This alarming trend emphasizes the growing sophistication and efficiency of AI-driven cyberattacks, which significantly outpace traditional human-led efforts. The use of autonomous agents capable of executing complex attack methods with minimal human oversight raises serious concerns for online security, pushing organizations to reevaluate their defenses. As the AI tools demonstrate remarkable adaptability, organizations must adopt a resilience-first approach to cybersecurity, honing their strategies to counter these increasingly prevalent and comprehensive threats.
Loading comments...
loading comments...