A hacker used AI agents to breach 100 companies and steal 600,000 card numbers
Working almost unattended, cheap AI agents scanned, broke into and skimmed data from dozens of retailers in days, for as little as $3 a target.
What happened: Between July and September 2026, a Chinese-speaking hacker ran a campaign that used AI agents to break into as many as 100 companies, according to security firm Gambit Security, which found the attacker's server left exposed online. In just five days in September, the agents launched 105 attack attempts and fully compromised at least 27 organizations, including a major hospitality chain, a US airline and an online fashion retailer. Investigators recovered more than 600,000 stolen, still-valid credit card numbers, about 488,000 of them belonging to Americans.
Why it matters: This is one of the largest confirmed cases of AI doing the bulk of a real cyberattack rather than just assisting a human hacker. The operator mostly typed short instructions in Chinese telling the AI what to do next; the AI itself found the vulnerabilities, wrote the exploit code, broke in, installed card-skimming scripts, and cleaned up evidence. Researchers say the AI showed more patience and inventiveness per target than most human attackers typically manage, at a fraction of the time and cost, which lowers the bar for who can run attacks like this.
How it works, plainly: The hacker combined three open-source AI 'harnesses': one to scan for weaknesses, one to autonomously exploit them for hours until it got in, and one to orchestrate the whole campaign. These ran on a mix of models: an older version of Anthropic's Claude, plus China's DeepSeek and Kimi models. Newer, better-guarded Claude versions refused the requests, so the attacker fell back on an older one. Total spend worked out to roughly $3 to $180 per targeted company, averaging about $25, because the AI needed almost no human hand-holding once given a target.
The rollout: Gambit Security is notifying affected companies and shared findings with Forbes; some victims have acknowledged the breach but not confirmed its scope. Cloudflare, whose servers hosted the attacker's infrastructure, has been taking it down, though the operator keeps standing up new servers. Anthropic says it banned the account behind the abuse. A separate anti-fraud firm, Overwatch Data, passed the stolen card data to payment processors, who confirmed most of it was previously unflagged, meaning the disclosure likely headed off further fraud.
