A Chinese Hacker Used AI To Attack 100+ Companies In One Of Largest AI Hacks Yet
Over just five days earlier this month, a Chinese-speaking hacker deployed AI agents to launch cyberattacks on as many as 100 organizations, stealing hundreds of thousands of credit card details. The hacker used Chinese models DeepSeek and Kimi as well as an older version of Anthropic’s Claude to automate their attacks, which cost just $8,000 in total.
It’s one of “the most severe abuses of AI for exploitation seen so far,” says Eyal Sela, a cybersecurity researcher and director of threat intelligence at Gambit Security, who discovered the attack.
“The human being is directing almost fully autonomous AI models, which are strong enough by now to do very sophisticated cyberattacks quickly with close to zero preparation and very high rate of success,” Sela says. Though the number of successful breaches out of the 100 companies is unclear, the hacker gained access to at least 30 websites between September 10 and 15, according to Gambit’s research.
Sela discovered the breaches after the hacker accidentally left the infrastructure used to carry out the attacks accessible on the web. That exposed stolen data, AI tooling and the prompts the hacker used, revealing a cheap and simple system to launch attacks at scale with minimum effort, Sela says. The cybercriminal behind the hack has not yet been identified, and the attacks appear to be ongoing.
For your first year. Renews at $135.99 annually
Subscriptions renew automatically. Taxes added at checkout. You may cancel your subscription at any time.
The breaches mark a milestone in the progress of AI-enabled cyberattacks. Earlier this year, OpenAI agents escaped containment and hacked into HuggingFace. In that instance, which was part of internal testing, the agents were caught before they could cause significant damage. In this case, a........
