Over just five days earlier this month, a Chinese-speaking hacker deployed AI agents to launch cyberattacks on as many as 100 organizations, stealing hundreds of thousands of credit card details. The hacker used Chinese models DeepSeek and Kimi as well as an older version of Anthropic’s Claude to automate their attacks, which cost just $8,000 in total.

It’s one of “the most severe abuses of AI for exploitation seen so far,” says Eyal Sela, a cybersecurity researcher and director of threat intelligence at Gambit Security, who discovered the attack.

“The human being is directing almost fully autonomous AI models, which are strong enough by now to do very sophisticated cyberattacks quickly with close to zero preparation and very high rate of success,” Sela says. Though the number of successful breaches out of the 100 companies is unclear, the hacker gained access to at least 30 websites between September 10 and 15, according to Gambit’s research.

Sela discovered the breaches after the hacker accidentally left the infrastructure used to carry out the attacks accessible on the web. That exposed stolen data, AI tooling and the prompts the hacker used, revealing a cheap and simple system to launch attacks at scale with minimum effort, Sela says. The cybercriminal behind the hack has not yet been identified, and the attacks appear to be ongoing.

The breaches mark a milestone in the progress of AI-enabled cyberattacks. Earlier this year, OpenAI agents escaped containment and hacked into HuggingFace . In that instance, which was part of internal testing, the agents were caught before they could cause significant damage. In this case, a malicious hacker used AI to attack multiple targets at astonishing speed.

“The number of targets… is astounding for that amount of time.” Sa’ar Elias, cofounder at Gambit Security

According to the hacker’s data, the victims include an American multinational hospitality company with over $10 billion in annual revenue; a major American airline, also with billions in revenue; and an online fashion retailer with over $1 billion revenue. The hacker also attacked a number of smaller companies, including a gun dealership based in Minnesota and a beauty retailer in Illinois. The hacker’s server contained details on at least 618,000 credit cards, though it’s unclear if they’ve been able to siphon off funds or use them to buy items. Anti-fraud cybersecurity startup Overwatch Data analyzed the credit card information and had high confidence the details were unique and legitimate. As many as 488,000 were credit cards owned by Americans.

“The number of targets and the sophistication for every one of those companies attacked is astounding for that amount of time. I spent almost a decade in incident response... Let me tell you, this is not something that I’m used to seeing,” says Sa’ar Elias, cofounder at Gambit.

Anthropic confirmed it had identified and banned the account being used to carry out the attacks. Neither Deepseek nor Kimi creator Moonshot had responded to requests for comment at the time of publication.

Israel-based Gambit is an AI-focused cybersecurity company that monitors companies’ cloud-based systems and was founded in 2024. It’s raised $60 million to date. The firm has uncovered a number of cybercriminal campaigns where the hackers leaned heavily on AI. Earlier this year, its researchers found Russian-speaking cybercriminals were using SpaceX’s Cursor to break into seven companies.

According to screenshots and logs Sela showed to Forbes , there’s evidence that the hacker started building out their infrastructure back in July. They used multiple open-source tools, including AI agent orchestrators called Cairn and Hermes. These tools allowed the hacker to combine premier AI lab models, including Claude Opus 4.6, an older version of Anthropic’s frontier AI model, and Deepseek v4.1-flash, released by the Beijing-based company earlier this month. In total, the attacks cost between $3 and $180 per target, according to the data obtained by Gambit.

Detailed logs left on the hacker’s server showed that when they tried to use more recent versions of Claude, they were blocked, indicating guardrails on the latest Anthropic models are working to prevent blatant cybercriminal use.

To carry out the hack, the perpetrator sent their agents a target website with orders to probe it for weaknesses. The attacker told Claude it was carrying out cybersecurity penetration tests. In one chat, they wrote to a Claude bot, “When a primary path is blocked, think laterally: Are there adjacent entry points? Can trust relationships be exploited? Are there gaps in the supply chain?” In another prompt, they wrote, “After extracting and downloading all card data, wipe the source fields in batches,” indicating they were trying to hide their tracks.

Elias tells Forbes the agents were remarkably persistent and inventive when it came to finding weaknesses. “What I was impressed by was the sheer amount of vectors the tools managed to dig up and find individually for every target,” Elias says. “Every target got its own treatment and… the AI did different things for different companies to gain the same outcome.”

If they gained access to the target web server, the agents were instructed to both steal data and install so-called “skimmers” on online retail systems, which siphon off credit card information as it’s entered onto a website form. They were then ordered to delete all evidence of their access to the site. Arjun Bisen, cofounder and CEO at Overwatch Data, says his company passed the information on to credit card companies. In one case, a payments processor had confirmed at least 60% of the cards they had checked hadn’t previously been flagged for fraud. “This suggests the findings helped prevent a significant amount of likely fraud,” Bisen says.

Sela and his team are in the process of disclosing the breaches to victim companies. Some have acknowledged the attack, according to emails seen by Forbes , though none has confirmed its severity. Gambit also contacted Cloudflare, the internet security and content delivery network that the attacker used to run their servers. Cloudflare confirmed it has since been shutting down the hacker’s infrastructure. But the criminals have swiftly set up new servers, Sela says.

AI’s cyberskills are now at the point where the most advanced models are more capable than most humans at identifying and exploiting software vulnerabilities. The rapid development has caused alarm, with Anthropic previously reporting on cybercriminals launching attacks with its tools and limiting the release of its most advanced models to select trusted parties. After the Hugging Face breach, and warnings from current and former employees about the potential rise of rogue AI that could endanger humanity, Anthropic and OpenAI called for a slowdown in development.

But cybercriminals don’t need access to the most powerful models to do damage. As this case shows, combining older American models and Chinese open-source AI can create a potent cyber arsenal.