Full Breakdown
Hackers Use Chinese AI Tools to Swipe Hundreds of Thousands of Credit Cards
By Drooid · · How we work
Campaign Overview
A Gambit Security investigation uncovered a coordinated cyber-crime operation that stole roughly 600,000 credit-card numbers from businesses in Europe, the Middle East and the United States. The campaign unfolded beginning on September 10 and continued for several days, with activity traced back to July. Hackers employed three open-source AI systems—an autonomous agent named Hermes, a scanning tool using GLM 5.2 and DeepSeek v4 Pro, and the penetration-testing engine Cairn—to automate attacks on at least 100 online retailers and service providers, including a Fortune 500 hospitality firm, a major U.S. airline, an industrial-supplies distributor and an online fashion retailer.
Technical Methodology
Hermes maintained a persistent memory and generated its own scripts, while the scanning tool mapped target sites. The total cost of the operation was estimated between $12,000 and $18,000, averaging $25 per scan; individual attacks ranged from just over $3 to as much as $79.
Scale and Financial Impact
Gambit’s report states that card-stealing malware was installed on the websites of five companies, and that the hackers gained some level of access to assets of the aforementioned high-profile firms. The theft of 600,000 credit-card numbers represents a breach of unprecedented scale for AI-augmented cybercrime.
Official Reactions
Bill Gates warned that the most dangerous aspect of artificial intelligence is not rogue behavior but its exploitation by malicious actors to conduct costly attacks. He emphasized that AI can enable fraud, disruption of critical infrastructure and large-scale financial theft at a fraction of traditional costs.
Verbatim Quotes
- “We estimate the actual size and impact of the campaign to be larger than we report,” — Eyal Sela, Director of Threat Intelligence at Gambit, in the official report
