A single Chinese-speaking operator used three open-source AI harnesses to compromise at least 27 companies and pull more than 600,000 credit card records, and the whole campaign cost about the price of a used car.
Gambit, an AI security firm, recovered the operator’s staging server and reconstructed the run. Between September 10 and September 15 the attacker launched at least 105 attacks, breaching companies in the Fortune 500 hospitality sector along with a major US airline, a large industrial supplies distributor and an online fashion retailer. Where access succeeded, it often took hours rather than weeks.
Three tools split the labor. Hermes Agent acted as orchestrator, loaded with a red team persona and 121 skills, 78 of them attack-focused. One skill stripped the harness’s content filters. Hermes ran on Claude Opus 4.6, with the operator typing 1,951 Chinese prompts across 260 sessions. Strix, a penetration-testing tool, hunted for openings. Cairn then ran each attack to completion, choosing paths in real time.
The economics are the story. Total model spend landed between $12,000 and $18,000, with a median scan costing $25.46 and the cheapest just $3.13. In two breaches the agents exfiltrated the card records together. The operator’s own playbook included cleanup routines that could delete a victim’s data, and Gambit says that damage occurred in some intrusions.
The lesson is blunt. Attack capability that once required a team now fits one wallet and a few paid API keys.
