With just a few lines of instructions, AI can find vulnerabilities, infiltrate systems, and even steal credit card information. The automation of cyberattacks is rapidly approaching an operational phase.

According to a September 22 report by security firm Gambit Security, financially motivated attackers utilized multiple open-source AI agents to target hundreds of online shops. In the period of September 10-15, 2026 alone, 105 attack projects were executed, with confirmed infiltrations into at least 27 companies.

The reported damages include over 600,000 credit card details leaked from two companies. Furthermore, on 19 of the 27 targeted sites, malicious scripts designed to steal card information directly from payment screens were embedded.

The attacks leveraged three distinct AI tools: “Strix” for vulnerability discovery, “Cairn” for executing infiltration, and “Hermes” for overall management. Attackers provided concise commands such as “Start after reviewing the vulnerability report” and “Enter the admin panel,” delegating much of the subsequent reconnaissance and attack operations to the AI.

Records confirmed by Gambit Security show that the AI usage fee for 101 scans averaged $25.46 per company. While this doesn't represent the total cost of the attacks, it highlights a drastic reduction in the expense of automatically surveying numerous companies and identifying potential targets.

The AI also adapted its attack methods based on the target environment. In successful access cases, infiltration took less than a day, sometimes just a few hours. In one incident, while attempting to erase its tracks, the AI inadvertently involved existing backups, leading to the deletion of 180 database tables.

With advancements in AI performance, known weaknesses can now be continuously sought out cheaply, quickly, and on a massive scale. The disparity between companies that take time to patch vulnerabilities and AI agents that iterate attempts every few hours suggests a significant disadvantage for defenders.