SECURITY Signal 367
AI harnesses enabled $3.13 scans in a 27-company breach run
A card-skimming campaign used Strix, Cairn and Hermes to automate reconnaissance and exploitation, with scans costing as little as $3.13.
The event shows how inexpensive AI agent frameworks can turn a human-directed intrusion into a high-volume, low-cost scanning workflow, raising the economic viability of large-scale attacks on diverse targets.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The campaign used three specialized open-source agent harnesses, Strix, Cairn and Hermes, to automate reconnaissance, exploitation and workflow orchestration.
Scans cost as little as $3.13, making broad vulnerability scanning economically feasible even with low success rates.
The operation targeted 27 companies across sectors, including a Fortune 500 hospitality firm, a major US airline and an online fashion retailer.
THE READ
What the cluster adds up to.
The breach demonstrates that AI agent frameworks can replace manual reconnaissance with autonomous, repeatable scanning cycles, reducing the human labor required for large-scale intrusion attempts.
Adopting such frameworks incurs costs primarily from model access fees, which can accumulate to thousands of dollars per campaign, but the per-scan expense remains low enough to justify extensive probing.
The attack stops working when defenders detect anomalous model usage patterns or block the specific open-source harnesses, as the workflow relies on continuous model calls and specialized tool chaining.
Because the operation leverages distinct agents for each stage, disrupting one component, such as disabling Strix’s reconnaissance module, breaks the automated pipeline, limiting the attacker’s ability to scale the campaign.
The lack of public victim acknowledgment means the full impact remains opaque, but the documented economics suggest that similar low-cost AI-driven attacks could become more prevalent if left unchecked.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗