Culture

AI Tools Let Hackers Breach Online Retailers for Just $25

Cybersecurity firm Gambit revealed that an attacker used open-source AI tools to breach 27 online retailers, demonstrating how cheap and efficient automated cyberattacks have become.

Computerworld AI1 day agoCulture
Image: Computerworld AI

An unidentified cybercriminal successfully compromised dozens of e-commerce platforms using automated artificial intelligence tools, operating at an incredibly low cost. According to a report by the Israeli cybersecurity firm Gambit, the attacker targeted 105 online retailers over a five-day period, successfully breaching 27 of them. The entire campaign was highly cost-effective, averaging just $25 per attack.

To orchestrate the campaign, the hacker utilized three distinct open-source AI frameworks. A tool named Strix was deployed to search for system vulnerabilities, while another called Cairn handled autonomous end-to-end exploitation. A third framework, Hermes, was used to coordinate the overall operation. The attacker accessed the underlying AI models through the API aggregator OpenRouter. Financial records from August 25 showed the attacker spent a total of $7,005 over a four-week period, with individual target costs ranging from a mere $3.13 to a maximum of $79.31.

The financial and security consequences of this AI-driven campaign are severe. Gambit reported that the attacker managed to steal 600,000 active credit card details from just two of the compromised businesses. Additionally, the hacker successfully injected malicious card-skimming scripts into five other online shops and gained varying levels of unauthorized access to several major corporations.

For cybersecurity professionals, this development signals a shift in the threat landscape. The speed and minimal cost of these incursions show how AI is lowering the barrier to entry for highly sophisticated, automated cybercrime. Gambit warned that these tools allow attackers to execute complex campaigns with a level of efficiency that human hackers would struggle to achieve manually, forcing defenders to adapt to rapid, machine-driven threats.

This is our own summary of reporting by Computerworld AI

More in Culture