MEDIUMApt
Global

AI tools help hacker break in for $25 per target

·Source: CSO Online

Updated:

Executive Summary

It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack, according to research by Israeli security company Gambit . But the attacks have been going on for much longer. Whoever is responsible used open-source AI harnesses to mount the attack. Gambit has identified

Analysis

It’s cheap to set yourself up as a hacker these days using AI. Someone attacked 105 online retailers over a period of five days, compromising 27 of them — all for an average of $25 per attack, according to research by Israeli security company Gambit . But the attacks have been going on for much longer. Whoever is responsible used open-source AI harnesses to mount the attack. Gambit has identified three of these: Strix for vulnerability search, Cairn for autonomous end-to-end exploitation, and Hermes to orchestrate the campaign. The attacks have proved to be highly lucrative, with 600,000 active credit card details taken from just two businesses, the installation of card skimmer scripts at five more, and some level of access to an unspecified number of major companies. It has been a highly efficient attack, most access taking just a few hours and at a minimal cost. OpenRouter was used for AI model access. The capture of the account balance on August 25 showed the attacker spent just $7,005 over a four-week period. This worked out at roughly $25 per attack, with costs ranging from $3.13 for the cheapest target to $79.31 for the most expensive. Gambit has contacted all the companies concerned, but warned that the intensity of the attacks shows how AI is transforming cyber criminals’ activities by providing a level of sophistication that humans would find more challenging to muster. We are already seeing a new level of incursions to businesses and can expect to see more in the future .
Source Attribution

Originally published by CSO Online on Sep 25, 2026.

Related Threats

MEDIUMApt

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that

The Hacker News
MEDIUMApt

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

The Hacker News
LOWApt

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT , deployed against Taiwanese appliances. Additionally, we provide source code details of the

Rapid7