Open-source AI campaign breached at least 27 companies, report finds
A Chinese-speaking criminal used three open-source AI tools to conduct at least 105 attacks against companies, compromising at least 27, including a Fortune 500 hospitality firm and a major US airline. The largely autonomous campaign stole more than 600,000 payment-card records, installed card-skimming software and sometimes risked operational disruption through data deletion.
The tools divided the work between vulnerability discovery, exploitation and orchestration, with the operator supplying 1,951 prompts across 260 sessions. The campaign cost an estimated $12,000–$18,000 overall, averaging $25.46 per completed scan; one documented breach involved SQL injection, a stolen one-time password, a web shell, privilege escalation and the theft of 46 secrets from AWS-related systems.
- AI agents enabled dozens of low-cost corporate attacks.
- At least 27 organisations were compromised.
- More than 600,000 payment-card records were stolen.
AI Americas Business Companies Health Medicine Technology World
Read the full article at the source →
Originally published by The Register as “Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs”.