Chinese Hacker Uses AI Agents To Steal 600,000 Credit Cards

Chinese Hacker Uses AI Agents in AI Cyberattack | Cyberpro Magazine

Key Takeaways: 

  • A hacker used automated AI tools to target online retail companies.
  • The active campaign stole more than 600,000 valid customer credit card records.
  • Researchers found that the AI cyberattack cost about $25 per targeted company on average.

A Chinese-speaking hacker used automated AI agents between September 10 and 15 to break into more than 100 companies and steal over 600,000 credit card records by taking advantage of software flaws.

Hacker Uses Automated Tools To Target Online Retailers

A financially motivated hacker launched a major cyberattack campaign against online retailers using automated software tools. Between September 10 and 15, the operation successfully broke into at least 27 companies through a series of rapid attacks. The hacker focused on vulnerable e-commerce platforms to steal as much data as possible.

Researchers from cybersecurity firm Gambit Security discovered the attack after finding a staging server exposed online and operated by the hacker. The attacker gave short instructions to the AI agents, which then handled system checks, searched for weaknesses, and took advantage of those flaws without needing step-by-step human input.

The attack allowed the automated tools to get around multi-factor authentication, gain administrator access, and take sensitive information from databases. In several cases, the agents placed malicious code on checkout pages to secretly collect payment card details as customers entered them across multiple affected websites around the world.

Researchers Identify The Tools And Low Attack Costs

The operation used three open-source tools called Strix, Cairn, and Hermes. Strix searched for security weaknesses, Cairn handled AI cyberattack that took advantage of those weaknesses, and Hermes acted as the main control system for running the wider campaign. Together, the tools helped carry out the attacks with limited human involvement.

The hacker used several paid AI models to run these tools, including DeepSeek, Kimi, and an older version of Claude. Since the automated system handled much of the difficult work, the cost of running the AI cyberattack stayed very low.

Records found on the staging server showed that the hacker spent about $25 per targeted company on average. The total cost of the campaign ranged from $12,000 to $18,000 across all completed scans and AI cyberattack, showing how cheaply large-scale cybercrime can be carried out.

Security Firms Work To Shut Down The Attackers’ Servers

Customers in the United States were affected the most, making up nearly 79 percent of all stolen payment cards. Major organizations, including a Fortune 500 hospitality company, a major U.S. airline, and an online fashion retailer, suffered significant data breaches during the campaign.

At one bicycle retailer, an aggressive cleanup process run by the automated agent deleted 180 database tables and destroyed internal backups. The unexpected data loss caused serious business problems for the company even after the initial attack had ended.

Security companies are now working with Cloudflare and the Shadowserver Foundation to shut down the servers used by the hacker. While security teams continue blocking active servers, investigators warn that similar automated AI cyberattack could become more common in the coming months.

Visit more of our news! CyberPro Magazine

LinkedIn
Twitter
Facebook
Reddit
Pinterest