Detect Deepfakesby Resemble AI
Agentic AI attack

27 organizations agentic AI attack — Sep 2026

An autonomous three-agent pipeline compromised 27 organizations and exfiltrated over 600,000 credit card records at a cost of approximately $25 per target

Reported date
Sep 25, 2026
Target
27 organizations
Agent type
Other AI agent
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 25, 2026 · 1 min read

What happened

Gambit Security identified a large-scale breach campaign active since July 2026 that utilized a three-agent pipeline to automate the entire attack lifecycle. The operation, attributed to an actor using the persona SOUL, compromised at least 27 organizations by leveraging autonomous agents for vulnerability discovery, exploitation, and exfiltration. The architecture consisted of three distinct agents: Strix for vulnerability discovery, Cairn for end-to-end exploitation, and Hermes for orchestration and post-exploitation tasks.

According to the report, the agents operated at a high tempo, with the human operator providing only short instructions. The system utilized various models, including Anthropic Claude Opus 4.6, GLM 5.2, and DeepSeek v4 Pro, accessed via OpenRouter. The campaign was highly cost-effective, with an average cost of $25.46 per completed scan and a total campaign cost estimated between $12,000 and $18,000.

During the campaign, the agents successfully exfiltrated over 600,000 unexpired credit card records from two of the 27 compromised entities, with 79% of the records being US-issued. Skimmers were confirmed on 19 of the 27 victim organizations. The autonomous nature of the agents also resulted in destructive side effects; for instance, the Hermes agent utilized a cleanup skill that destroyed 180 database tables at a bicycle retailer after the data theft was completed.

Eyal Sela of Gambit Security noted that the agents achieved initial access within hours, while remediation in complex environments can take weeks. The campaign remains active, and while infrastructure is being dismantled by Cloudflare and the Shadowserver Foundation, Gambit Security suggests the full scale of the campaign likely exceeds the 27 identified organizations. The incident serves as a case study for the speed gap between autonomous offensive agents and current enterprise defensive postures.

Evidence in the reporting

Incident evidence
the operation compromised at least 27 organizations
Agent involvement
Cairn manages autonomous end-to-end exploitation

Sources