A group of hackers stole over half a million credit cards from Europe, the Middle East, and the US in fewer than 100 attacks targeting online businesses using Chinese artificial intelligence models, a report by Gambit Security revealed last week.
According to the report, hackers used Chinese AI software that cost 25$ per attack and only required the use of simple prompts such as “Identify vulnerabilities in the system and break in."
In total, 600,000 credit cards were stolen from two companies, card-stealing software was installed on the sites of five companies, and some level of access was gained to the assets of companies including a Fortune 500 hospitality company, a major US airline, a large private US industrial supplies distributor, and a US online fashion retailer.
The attack also ran almost autonomously, with hackers entering simple prompts into three AI harnesses that let them target tens of companies a day. The 100 reported attacks occurred from September 10 to 15, with similar activity detected as early as July and still ongoing.
"We estimate the actual size and impact of the campaign to be larger than we report," said Eyal Sela, Director of Threat Intelligence at Gambit, in the official report.
Using three systems to target thousands of companies
The report said the campaigns used three open-source AI tools, with the estimated final cost between $12,000 and $18,000, or $25 per scan; the cheapest operation cost just over $3, and the most expensive attack cost up to $79.
The campaign was orchestrated through Hermes, which Gambit described as "an open-source autonomous AI agent with a persistent memory, skills that the agent writes and edits itself, a searchable archive of past sessions, scheduled jobs, and a web console."
The scanning was done using the open-source AI penetration testing tool, which focused on scanning the targeted sites and used further models such as GLM 5.2 and DeepSeek v4 Pro.
Finally, the attacks were done using Cairn, an autonomous penetration testing engine that is able to target domains with simple instructions or objectives, such as "get a shell or admin access, then run for hours until it achieves the objective, times out, or is stopped," Gambit explained.
Bill Gates warns about ill-intentioned actors' use of AI
This type of attack was exactly what Microsoft founder Bill Gates warned about during an interview with NBC on Sunday, where he said that the main risk of AI is not the fact that it can become rogue, but that it can be used by ill-intentioned actors to perform attacks that would have cost millions of dollars without AI.
"The most dangerous thing about AI is people's bad intentions using it for things like defrauding individuals, shutting down electrical systems, or scrambling bank accounts," he said during his interview.
"There has never been a weapon as powerful as the combination of people with ill intentions using the latest AI tools," Gates claimed, and pointed out that it's a great sign that leaders in the industry and policymakers are worried about this situation.