conv.

All stories
SecurityActive · 41h

Chinese hacker used AI agents to breach up to 100 companies, steal 600,000+ cards

Gambit Security says a lone Chinese-speaking hacker spent about $8,000 on AI agents to automate a five-day hacking spree across dozens of firms.

What to know

  • A single Chinese-speaking hacker used off-the-shelf AI orchestration frameworks (Strix, Cairn, Hermes) driving Claude Opus 4.6, DeepSeek and Kimi to scan and breach up to 100 companies in five days.
  • Total spend was about $8,000 ($3.13–$79.31 per target) to steal over 600,000 credit card records, about 79% belonging to American cardholders.
  • Newer Claude models refused to run the attack, suggesting stronger guardrails in Anthropic's latest releases; Anthropic has banned the account tied to the older-model abuse.
  • Cloudflare and Shadowserver Foundation are trying to dismantle the hacker's infrastructure, but the attacker has repeatedly rebuilt servers and attacks are ongoing.

“the most severe abuses of AI for exploitation seen so far”

Eyal Sela, Director of threat intelligence, Gambit Security · Forbes (via Quartz) ↗ · Sep 21

Eyal Sela Director of threat intelligence, Gambit SecurityAnthropic Maker of Claude AI modelsCloudflare Infrastructure provider assisting takedownChinese-speaking hacker Unnamed attacker behind the campaignShadowserver Foundation Nonprofit security organization

Chinese hacker used AI agents to breach up to 100 companies, steal 600,000+ cards
qz.com

How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts

Peak 2 pieces in one hour at Sep 22, 12 PM; 6 pieces over 42 hours (2 articles · 4 posts) Sep 22, 6 AM — 1 piece · 1 post — Mastodon 1Sep 22, 7 AM — quietSep 22, 8 AM — quietSep 22, 9 AM — quietSep 22, 10 AM — quietSep 22, 11 AM — 1 piece · 1 post — Mastodon 1Sep 22, 12 PM — 2 pieces · 1 article · 1 post — Mastodon 1, Newswires 1Sep 22, 1 PM — quietSep 22, 2 PM — quietSep 22, 3 PM — quietSep 22, 4 PM — quietSep 22, 5 PM — quietSep 22, 6 PM — quietSep 22, 7 PM — quietSep 22, 8 PM — quietSep 22, 9 PM — quietSep 22, 10 PM — quietSep 22, 11 PM — quietYesterday, 12 AM — quietYesterday, 1 AM — 1 piece · 1 post — Mastodon 1Yesterday, 2 AM — quietYesterday, 3 AM — quietYesterday, 4 AM — quietYesterday, 5 AM — quietYesterday, 6 AM — quietYesterday, 7 AM — quietYesterday, 8 AM — quietYesterday, 9 AM — quietYesterday, 10 AM — quietYesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — quietYesterday, 2 PM — quietYesterday, 3 PM — quietYesterday, 4 PM — quietYesterday, 5 PM — quietYesterday, 6 PM — 1 piece · 1 article — Mastodon 1Yesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quiet 12
8 AM4 PMyesterday8 AM4 PMnow · 12:57 AM ET
  1. 2

    Quartz details cost, frameworks and stolen-card totals

    Quartz's writeup lays out the $3–$79 per-target spending, the Strix/Cairn/Hermes orchestration frameworks, and confirms 488,000 of the 600,000+ stolen records belonged to U.S. cardholders.

    “The human being is directing almost fully autonomous AI models, which are strong enough by now to do very sophisticated cyberattacks quickly with close to zero preparation and very high rate of success…”
    — Eyal Sela
    • z_everson

      "A Chinese Hacker Used AI To Attack 100+ Companies In One Of Largest AI Hacks Yet" Thomas Fox Brewster for Forbes # tech # AI # news https://www. forbes.com/sites/thomasbrewste r/2026/09/22/huge-cyberattack-uses-anthropic-and-deepseek-ai-to-target-100-companies/

      z_eversonMastodon1d ago6▲view on Mastodon ↗
    1 more of the top 2 · 2 posts in this stretch
    • clarinette@mastodon.online

      « Over just five days earlier this month, a Chinese-speaking hacker deployed AI agents to launch cyberattacks on as many as 100 organizations, stealing hundreds of thousands of credit card details. The hacker used Chinese models # deepseek and Kimi as well as an older version of # Anthropic ’s # Claude to automate their attacks, which cost just…

      clarinette@mastodon.onlineMastodon22h ago1▲view on Mastodon ↗
    all of them →
  2. background

    Cloudflare and Shadowserver move to dismantle hacker's servers — Gambit Security is notifying affected companies while working with Cloudflare and the Shadowserver Foundation to take down the attacker's infrastructure; Cloudflare confirmed shutting down servers, though the attacker keeps rebuilding them and the campaign continues.

  3. background

    Anthropic bans account tied to the attack — Anthropic confirmed it identified and banned the account used in the campaign; newer Claude releases reportedly refused to run the attack, unlike the older Claude Opus 4.6 used by the hacker.

  4. 1

    Forbes breaks the AI-hacking campaign story

    Forbes reports that Gambit Security uncovered the operation after the attacker left server infrastructure exposed on the open web, revealing the scale of the AI-orchestrated intrusion.

    “A Chinese Hacker Used AI To Attack 100+ Companies In One Of Largest AI Hacks Yet…”
    — Forbes
    • A Chinese Hacker Used AI To Attack 100+ Companies In One Of Largest AI Hacks Yet https://www. forbes.com/sites/thomasbrewste r/2026/09/22/huge-cyberattack-uses-anthropic-and-deepseek-ai-to-target-100-companies/?utm_source=flipboard&utm_medium=activitypub Posted into Daily Cover Stories @ daily-cover-stories-forbes

      forbes@flipboard.comMastodon1d agoview on Mastodon ↗
  5. background

    Attacker plants checkout skimmers and wipes access logs — Agents were directed to exfiltrate payment records and install skimmers on checkout pages, then erase evidence of access; in at least two cases the cleanup wiped victims' own data and backup tables entirely.

  6. background

    Hacker launches five-day AI-driven breach campaign — Using AI agents built on Claude Opus 4.6, DeepSeek and Kimi, the attacker compromised at least 27 companies between September 10 and 15, including a Fortune 500 hospitality firm, a major U.S. airline, an industrial supplies distributor, and an online fashion retailer.

What people are saying 0 voices from 0 sites · best of 3 · verbatim