Gambit research finds AI tools breach retailers for $25 per target
AI Tools Enable the Attacker to Breach Online Retailers for $25 Per Target
Artificial intelligence harnesses are lowering the financial and technical barriers to cybercrime, allowing a person to compromise 27 out of 105 targeted online retailers for an average cost of $25 per attack over a five-day span, according to research published by Israeli security company Gambit.
The Tech TL;DR: Automated Exploitation Metrics
Attack Efficiency: Gambit’s research details how an attacker attacked 105 online retailers over five days, successfully compromising 27 targets using open-source AI harnesses at an average cost of $25 per incursion.
Toolchain Architecture: The campaign utilized Strix for vulnerability scanning, Cairn for autonomous end-to-end exploitation, and Hermes for campaign orchestration, with model access via OpenRouter.
Financial Impact: Total spending tracked via an OpenRouter account balance update on August 25 reached $7,005 over a four-week span, yielding high-value returns including 600,000 active credit card records from just two compromised businesses.
Anatomy of an Automated Cyberattack Campaign
The campaign relied on an orchestrated stack of open-source artificial intelligence harnesses rather than bespoke human-written exploits. According to Gambit’s findings, the attacker deployed Strix to map out vulnerabilities across target infrastructures, followed by Cairn to execute autonomous end-to-end exploitation. A third tool, Hermes, managed the overarching orchestration of the multi-pronged operation.
Model inference was handled via OpenRouter, allowing the attacker to cycle through underlying language models efficiently. Monitoring of an OpenRouter account balance on August 25 revealed total expenditures of $7,005 over a four-week window. Individual attack costs scaled depending on target complexity, starting as low as $3.13 for the cheapest target and peaking at $79.31 for the most expensive, averaging out to roughly $25 per successful penetration.
Monetization and Operational Scale
The financial return on investment for the attacker proved substantial. Gambit documented that the operations yielded 600,000 active credit card details extracted from just two of the targeted businesses. The attacker also installed malicious card-skimmer scripts across five additional e-commerce platforms and secured varying levels of unauthorized access to an unspecified number of major corporate networks.
Most individual target incursions were executed within a matter of hours. Gambit warned that the intensity and speed of these automated campaigns demonstrate how artificial intelligence is fundamentally transforming offensive cyber operations. The technology provides a level of operational sophistication and velocity that human teams typically require significantly more resources to muster, pointing toward an incoming wave of scalable incursions against enterprise targets.
Mitigating Automated Threat Vectors
In response to the campaign, Gambit reported that it has contacted all the companies affected by the breaches.
Disclaimer: The technical analyses and security protocols detailed in this article are for informational purposes only.