All Insights

A Solo Operator Hacked 27 Companies for $18K Using Open-Source AI Agents

CivSafe Team·September 28, 2026·5 min read

On September 22, a cybersecurity firm called Gambit Security published a report that should be required reading for anyone who stores customer data. A solo attacker -- working under the alias SOUL -- used three open-source AI agents to autonomously breach at least 27 organizations. The haul: 600,000+ unexpired credit card records. The cost to the attacker: roughly $25 per target. About $18,000 total.

One of those 27 targets was a bicycle retailer. After the agents finished exfiltrating payment data, they automatically wiped 180 of the company's database tables -- backups included.

This is not an enterprise story. This is your story.

What Actually Happened

The three tools at the center of this -- Strix, Cairn, and Hermes -- didn't start life as attack tools. Strix and Cairn were legitimate, community-built penetration testing frameworks: the kind of thing security consultants use to simulate attacks and find vulnerabilities before real attackers do. Hermes is a general-purpose autonomous agent with persistent memory and the ability to rewrite its own capabilities.

SOUL loaded a brief set of instructions into Hermes. Hermes coordinated Strix and Cairn. Strix scanned targets and hunted for vulnerabilities. Cairn exploited them until it had shell access or admin credentials -- often within hours of finding the flaw. Hermes handled everything after: post-exploitation, data staging, cleanup, tactical steering.

The whole pipeline ran, as The Register reported on September 25, "at a tempo no human operator sustains, with the person reduced to short instructions between autonomous runs."

Between September 10 and 15, this pipeline executed 105 attacks against 138 hosts. One person. Five days. No team required.

Why This Hits Different

The victims here read like a cross-section of the organizations we work with every day. Yes, a Fortune 500 hotel chain. Yes, a major US airline. But also: an online fashion retailer, an industrial supplies distributor, and a bicycle shop.

The agents specifically targeted e-commerce platforms and payment flows -- hunting stored card data in PCI-adjacent systems where a lot of smaller organizations are exposed because they outsourced "compliance" to a plugin and moved on.

At $25 per target, this is now economically accessible to anyone with a basic understanding of how these tools work. Before AI agents, running 105 attacks in five days against 138 hosts required a team and serious operational overhead. SOUL did it alone, with commodity infrastructure and open-source tools that are freely available right now.

That's the shift. Not "AI is making hackers faster." It's that the unit economics of a multi-target breach campaign have collapsed.

What You Actually Do About It

This isn't a "patch your software" post -- you already know that. But there are specific things worth acting on given how this campaign worked.

Find out what card data actually touches your systems. The agents were hunting payment data. If you're using a third-party processor correctly, raw card numbers should never hit your database. If you're not certain that's true for your setup, find out this week -- not next quarter.

Rethink your backup posture. Hermes includes a cleanup skill that wiped a victim's database after extraction. "We back up to S3" isn't enough if the same credentials that access your database can also access your backups. Air-gapped, off-site copies of your most critical data are no longer a nice-to-have.

Shrink your public attack surface. Strix automated vulnerability discovery at scale. If you have unpatched plugins, forgotten staging servers, or legacy integrations sitting publicly accessible, assume they're being scanned right now. The campaign was still active when Gambit published.

Check your monitoring for agent-shaped traffic. These tools generate distinctive patterns -- rapid sequential requests, automated recon flows, unusual API call chains. If you're not logging and alerting on this kind of behavior, you won't know you're being probed until it's too late.

The Bigger Picture

The piece of this that matters most for small organizations isn't the technical sophistication of the attack. It's that the barrier to entry dropped far enough that a single person can run a 27-target campaign over a long weekend.

Strix and Cairn are legitimate tools. Security researchers use them for good reason. What changed is that a general-purpose orchestration layer -- Hermes -- can now coordinate multiple specialized agents toward a hostile goal, running continuously, adapting based on what it finds, and cleaning up after itself.

The tools are public. The playbook is documented. The economics are solved.

Small organizations can't outspend this threat. What you can do is reduce the surface, know what data you're holding and why, and make sure that when automated agents come scanning -- and they are, right now -- there's nothing worth finding, and nothing worth wiping.

If you're not sure where to start with any of that, it's exactly what we help with.


Source: Gambit Security report | The Register coverage, September 25 2026 | CyberSecurityNews

CivSafe — Strategic Innovation. Community Impact.