A Chinese-speaking hacker used AI agents to target as many as 100 organizations in five days, with researchers finding details for at least 618,000 credit cards on the attacker’s server. The reported cost of the operation was just $8,000.
The attacker combined DeepSeek, Kimi and an older version of Anthropic’s Claude to automate the campaign, according to Forbes, citing research by Gambit Security.
Gambit’s threat intelligence director, Eyal Sela, described it as:
“One of the most severe abuses of AI for exploitation seen so far.”
What Was Actually Breached?
Researchers found evidence that the hacker accessed at least 30 websites between September 10 and 15. The total number of successfully breached organizations remains unclear, so the findings do not establish that all 100 targets were compromised.
According to data recovered from the attacker, victims included:
- An American hospitality company with more than $10 billion in annual revenue.
- A major US airline generating billions in revenue.
- An online fashion retailer with revenue above $1 billion.
- Smaller businesses, including a Minnesota gun dealership and an Illinois beauty retailer.
The server held at least 618,000 credit card records, but whether the attacker used them to steal money or make purchases remains unknown.
How the Campaign Was Discovered
The hacker accidentally left attack infrastructure exposed online, allowing researchers to examine stolen data and activity logs.
Anthropic said it identified and banned the account involved. Forbes also reported that attempts to use newer Claude versions were blocked. DeepSeek and Kimi developer Moonshot had not responded by publication.
Related: Top AI Leaders Call for Slowing Down AI Development.
Why This Matters
This was a human-directed criminal campaign using AI to automate attacks. It shows how one attacker can attempt breaches across many businesses within days, with a relatively small budget.
The findings also add urgency to the debate over whether existing safeguards and enforcement can keep pace with increasingly capable AI tools.
Related: Trump Rejects AI Slowdown Calls, Citing Competition With China.
The warning is the combination of speed, scale and cost: a single attacker reportedly targeted around 100 organizations for $8,000, while the full damage is still being established.


