An icon of an eye to tell to indicate you can view the content by clicking
Signal
Original article date: Sep 25, 2026

AI-Powered Attacks on Retailers Now Cost Just $25: A Case Study in Automated Hacking at Scale

September 25, 2026
•
5 min read

New research from Israeli security firm Gambit has documented a real-world AI-powered attack campaign that compromised 27 online retailers out of 105 targeted, at an average cost of just $25 per successful breach. The case illustrates how agentic AI tools are actively lowering the barrier to sophisticated cyberattacks.

Key Takeaways

  • $25 per breach, end to end - The attacker spent $7,005 over a four-week period attacking 105 retailers, with per-target costs ranging from $3.13 to $79.31. OpenRouter was used to access AI models at low cost.
  • Three open-source AI tools orchestrated the attack - Strix handled vulnerability discovery, Cairn performed autonomous end-to-end exploitation, and Hermes orchestrated the campaign. All three are open-source AI harnesses, meaning the underlying tools are publicly available.
  • Damage was severe - 600,000 active credit card details were taken from just two businesses. Card skimmer scripts were installed at five additional retailers. Several major companies also experienced unauthorized access.
  • Businesses cannot rely on complexity as a defense - The attacker's success came not from technical sophistication that only a nation-state could afford, but from AI automation of well-understood attack techniques. Most compromises took just a few hours.

Gambit has notified all affected companies, but the broader warning is clear: AI is giving cybercriminals capabilities that match or exceed what human experts could achieve, at a fraction of the cost.

Read the full article on Computerworld