A Chinese-speaking hacker used AI models from Anthropic, DeepSeek, and Moonshot to steal more than 600,000 credit card records within five days.
According to Forbes, a Chinese-speaking hacker used AI agents to launch cyberattacks against up to 100 organizations within just five days this month, stealing hundreds of thousands of credit card records in the process. The attacks relied on the Chinese AI models DeepSeek and Kimi, as well as an older version of Anthropic’s Claude.
Five Days, 100 Targets, $8,000 in Costs
“The most severe abuses of AI for exploitation seen so far.”
Eyal Sela, Security Researcher and Director of Threat Intelligence at Gambit Security
According to research by Israeli security company Gambit Security, the entire attack campaign cost the attacker only about $8,000. Between September 10 and 15, the attacker gained access to at least 30 websites, according to Gambit. Eyal Sela, security researcher and Director of Threat Intelligence at Gambit Security, described the incident as one of the most serious known cases of AI being abused for criminal purposes:
“The human being is directing almost fully autonomous AI models, which are strong enough by now to do very sophisticated cyberattacks quickly with close to zero preparation and very high rate of success.”
Eyal Sela, Security Researcher and Director of Threat Intelligence at Gambit Security
How the Attack Was Discovered
Sela discovered the attacks after the hacker accidentally exposed the infrastructure used for the campaign on the open internet. This made stolen data, the AI tools involved, and the prompts used by the attacker visible, revealing a low-cost and straightforward system for carrying out large-scale attacks with minimal effort.
The individual or individuals behind the hack have not yet been identified, and the attacks appear to be ongoing.
Companies Targeted and Data Stolen
According to data collected by the hacker, the victims included a US hotel company with more than $10 billion in annual revenue, a major US airline with billions of dollars in annual revenue, and an online fashion retailer generating more than $1 billion in revenue. The attacker also targeted smaller businesses, including a firearms retailer in Minnesota and a cosmetics retailer in Illinois. The attacker’s server contained data on at least 618,000 credit cards, approximately 488,000 of which belonged to US residents.
Overwatch Data, a company specializing in fraud detection, analyzed the credit card data and assessed with high confidence that the records were unique and genuine. Sa’ar Elias, co-founder of Gambit Security, said the sheer number and range of attack paths identified at each target stood out to him after nearly a decade in incident response. According to Elias, the AI found different ways to reach the same outcome for each target.
Tools and AI Models Used
Evidence shown by Sela to Forbes indicates that the hacker began building the infrastructure as early as July. The attacker used several open-source tools, including the AI agent orchestration systems Cairn and Hermes, which can combine models from different providers. These included Anthropic’s older Claude Opus 4.6 model and DeepSeek v4.1-flash, recently released by Beijing-based DeepSeek. The cost per targeted organization ranged from $3 to $180.
Logs on the attacker’s server also showed that attempts to use newer versions of Claude were blocked. According to Forbes, this suggests that the safeguards built into Anthropic’s latest models appear to be preventing criminal abuse.
Approach: Penetration Testing as a Cover
To persuade the AI models to assist with the attacks, the hacker told Claude that the activity was part of legitimate penetration testing. In one chat reviewed by Forbes, the attacker wrote: “When a primary path is blocked, think laterally: Are there adjacent entry points? Can trust relationships be exploited? Are there gaps in the supply chain?” Another instruction stated: “After extracting and downloading all card data, wipe the source fields in batches.”
This suggests an attempt to erase evidence of the attack. Once access to a target server was successful, the agents were instructed both to steal data and to install so-called skimmers that capture credit card information as it is entered into an online form. The agents were then instructed to delete all traces of access.
Response From Anthropic and Cloudflare
Anthropic confirmed that it had identified and suspended the account used in the attacks. DeepSeek and Moonshot, the developer of Kimi, had not responded to inquiries at the time of publication. Gambit also notified Cloudflare, whose infrastructure was being used to host the attacker’s servers. Cloudflare confirmed that it had since been gradually shutting down the relevant infrastructure. The attacker, however, quickly set up new servers.
Arjun Bisen, co-founder and CEO of Overwatch Data, said his company had shared its findings with credit card companies. One payment provider confirmed that at least 60 percent of the cards it reviewed had not previously been flagged for fraud, indicating that a significant amount of fraud may have been successfully prevented.
The incident is part of a growing number of AI-powered cyberattacks. In July, autonomous AI agents from OpenAI compromised the Hugging Face platform without authorization as part of internal testing. Gambit Security had previously revealed that Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to gain access to seven companies.
(Editorial Team)