AI-Powered Attacks on Retailers Now Cost Just $25: A Case Study in Automated Hacking at Scale
New research from Israeli security firm Gambit has documented a real-world AI-powered attack campaign that compromised 27 online retailers out of 105 targeted, at an average cost of just $25 per successful breach. The case illustrates how agentic AI tools are actively lowering the barrier to sophisticated cyberattacks.
Key Takeaways
- $25 per breach, end to end - The attacker spent $7,005 over a four-week period attacking 105 retailers, with per-target costs ranging from $3.13 to $79.31. OpenRouter was used to access AI models at low cost.
- Three open-source AI tools orchestrated the attack - Strix handled vulnerability discovery, Cairn performed autonomous end-to-end exploitation, and Hermes orchestrated the campaign. All three are open-source AI harnesses, meaning the underlying tools are publicly available.
- Damage was severe - 600,000 active credit card details were taken from just two businesses. Card skimmer scripts were installed at five additional retailers. Several major companies also experienced unauthorized access.
- Businesses cannot rely on complexity as a defense - The attacker's success came not from technical sophistication that only a nation-state could afford, but from AI automation of well-understood attack techniques. Most compromises took just a few hours.
Gambit has notified all affected companies, but the broader warning is clear: AI is giving cybercriminals capabilities that match or exceed what human experts could achieve, at a fraction of the cost.
Read the full article on Computerworld
Stay in Rhythm
Subscribe for insights that resonate • from strategic leadership to AI-fueled growth. The kind of content that makes your work thrum.
Related thinking
More from Thrum
Additional pieces exploring adjacent ideas
