Chinese hacker used AI agents to breach up to 100 companies, steal 600,000+ cards
Gambit Security says a lone Chinese-speaking hacker spent about $8,000 on AI agents to automate a five-day hacking spree across dozens of firms.
What to know
- A single Chinese-speaking hacker used off-the-shelf AI orchestration frameworks (Strix, Cairn, Hermes) driving Claude Opus 4.6, DeepSeek and Kimi to scan and breach up to 100 companies in five days.
- Total spend was about $8,000 ($3.13–$79.31 per target) to steal over 600,000 credit card records, about 79% belonging to American cardholders.
- Newer Claude models refused to run the attack, suggesting stronger guardrails in Anthropic's latest releases; Anthropic has banned the account tied to the older-model abuse.
- Cloudflare and Shadowserver Foundation are trying to dismantle the hacker's infrastructure, but the attacker has repeatedly rebuilt servers and attacks are ongoing.
“the most severe abuses of AI for exploitation seen so far”
Eyal Sela, Director of threat intelligence, Gambit Security · Forbes (via Quartz) ↗ · Sep 21
Eyal Sela Director of threat intelligence, Gambit SecurityAnthropic Maker of Claude AI modelsCloudflare Infrastructure provider assisting takedownChinese-speaking hacker Unnamed attacker behind the campaignShadowserver Foundation Nonprofit security organization
How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts
-
2
Quartz details cost, frameworks and stolen-card totals
Quartz's writeup lays out the $3–$79 per-target spending, the Strix/Cairn/Hermes orchestration frameworks, and confirms 488,000 of the 600,000+ stolen records belonged to U.S. cardholders.
“The human being is directing almost fully autonomous AI models, which are strong enough by now to do very sophisticated cyberattacks quickly with close to zero preparation and very high rate of success…”
— Eyal Sela -
Z
"A Chinese Hacker Used AI To Attack 100+ Companies In One Of Largest AI Hacks Yet" Thomas Fox Brewster for Forbes # tech # AI # news https://www. forbes.com/sites/thomasbrewste r/2026/09/22/huge-cyberattack-uses-anthropic-and-deepseek-ai-to-target-100-companies/
1 more of the top 2 · 2 posts in this stretch
-
C
« Over just five days earlier this month, a Chinese-speaking hacker deployed AI agents to launch cyberattacks on as many as 100 organizations, stealing hundreds of thousands of credit card details. The hacker used Chinese models # deepseek and Kimi as well as an older version of # Anthropic ’s # Claude to automate their attacks, which cost just…
-
-
background
Cloudflare and Shadowserver move to dismantle hacker's servers — Gambit Security is notifying affected companies while working with Cloudflare and the Shadowserver Foundation to take down the attacker's infrastructure; Cloudflare confirmed shutting down servers, though the attacker keeps rebuilding them and the campaign continues.
-
background
Anthropic bans account tied to the attack — Anthropic confirmed it identified and banned the account used in the campaign; newer Claude releases reportedly refused to run the attack, unlike the older Claude Opus 4.6 used by the hacker.
-
1
Forbes breaks the AI-hacking campaign story
Forbes reports that Gambit Security uncovered the operation after the attacker left server infrastructure exposed on the open web, revealing the scale of the AI-orchestrated intrusion.
“A Chinese Hacker Used AI To Attack 100+ Companies In One Of Largest AI Hacks Yet…”
— Forbes -
A Chinese Hacker Used AI To Attack 100+ Companies In One Of Largest AI Hacks Yet https://www. forbes.com/sites/thomasbrewste r/2026/09/22/huge-cyberattack-uses-anthropic-and-deepseek-ai-to-target-100-companies/?utm_source=flipboard&utm_medium=activitypub Posted into Daily Cover Stories @ daily-cover-stories-forbes
-
-
background
Attacker plants checkout skimmers and wipes access logs — Agents were directed to exfiltrate payment records and install skimmers on checkout pages, then erase evidence of access; in at least two cases the cleanup wiped victims' own data and backup tables entirely.
-
background
Hacker launches five-day AI-driven breach campaign — Using AI agents built on Claude Opus 4.6, DeepSeek and Kimi, the attacker compromised at least 27 companies between September 10 and 15, including a Fortune 500 hospitality firm, a major U.S. airline, an industrial supplies distributor, and an online fashion retailer.