🤖 AI Summary
Gambit researchers have uncovered a massive ongoing cyberattack attributed to Chinese threat actors, employing AI agents to launch an extensive skimming campaign that has compromised over 600,000 payment records since July 2026. Utilizing three autonomous frameworks—Strix, Cairn, and Hermes—attackers effectively targeted dozens of retail sites, achieving a startlingly low operational cost of approximately $25 per target. The campaign has notably impacted major U.S. firms, including a Fortune 500 hospitality company and a prominent airline, showcasing the alarming capabilities of AI in conducting persistent, large-scale cyberattacks.
The significance of this campaign lies in its demonstration of how AI technology can streamline and lower the cost of malicious activities, allowing attackers to execute complex operations with minimal human intervention. Hermes, one of the key AI agents, operates with persistent memory and can autonomously conduct attacks based on simple human prompts. This evolving threat model highlights a critical need for organizations to adopt a resilience-first approach to cybersecurity. As attacks become faster and more sophisticated, the AI/ML community must innovate defenses capable of matching this rapid pace to protect sensitive information and maintain operational integrity.
Loading comments...
login to comment
loading comments...
no comments yet