Gambit reveals hacker compromised 27 online retailers using AI

Open-source AI harnesses are lowering the cost of cyberattacks, with research from Israeli security company Gambit revealing a hacker compromised 27 out of 105 online retailers over five days for an average cost of just $25 per target using OpenRouter for model access.

The economics of automated cybercrime have hit a grim new milestone. Threat actors are no longer relying solely on expensive, bespoke custom scripts or massive botnets requiring deep technical overhead. Instead, they are stitching together modular open-source AI frameworks to run autonomous, end-to-end campaigns at a fraction of traditional operational costs.

Inside the Open-Source AI Hacker Toolkit

Gambit’s security analysis outlines a distinct three-pronged toolchain deployed in the campaign. The operator used Strix for automated vulnerability searches, Cairn to handle autonomous end-to-end exploitation, and Hermes to orchestrate the entire multi-target campaign.

By using these open-source harnesses, the attacker managed to compromise 27 out of 105 targeted online retailers over a five-day observation window. But the scope of the operation extends far beyond this brief snapshot. The attacks have been ongoing for a much longer period, resulting in high-yield data harvesting, including the acquisition of 600,000 active credit card details from just two victimized businesses. The attacker also successfully installed malicious card skimmer scripts at five additional sites while securing varying levels of unauthorized access to an unspecified number of major corporations.

Speed and efficiency define the operation. Most system breaches took just a few hours to execute from initial reconnaissance to final payload delivery.

Breaking Down the API Economics of an Attack

The financial ledger of the operation exposes just how inexpensive automated exploitation has become. Utilizing OpenRouter to route requests to underlying large language models, the attacker’s spending was tracked via account balance captures.

Gambit reveals hacker compromised 27 online retailers using AI
Photo: csoonline.com

A balance check on August 25 revealed a total expenditure of just $7,005 over a four-week operational period. When distributed across the campaign volume, this translates to an average cost of roughly $25 per attack target. The granular cost breakdown ranged from a mere $3.13 for the cheapest target up to $79.31 for the most complex enterprise environment encountered.

Gambit has already contacted all of the impacted companies regarding the breaches.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

PlayStation Engages Publishers Over Post-2028 Physical Media

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.