Tendvane

← All articles

SecuritySeptember 24, 2026

Nobody sat at a keyboard for this one. It cost 25 dollars a company.

Twenty-five dollars and forty-six cents. That was the average cost of breaking into one company.

Gambit Security reached the staging server of a financially motivated attacker and published what was on it on 22 September. The operator, who left short instructions written in Chinese, had bolted together three open-source AI agent tools: one to hunt for weaknesses, one to exploit what it found, and an orchestrator called Hermes loaded with 121 skills, 78 of them offensive. A few lines of direction went in at the top. The agents handled the rest, frequently getting inside a target in under a day.

The figures come from the attacker's own bookkeeping. Between 10 and 15 September the setup ran 105 attack projects and got into at least 27 organisations, including hospitality chains, US airlines, industrial suppliers and fashion retailers. Payment skimmers went up on 119 websites. Over 600,000 unexpired card records came out of just two victims. Four weeks of AI model bills came to somewhere between $12,000 and $18,000, with individual companies costing between $3.13 and $79.31.

A skimmer is a few lines of JavaScript on a checkout page, reading the card number as it is typed. You cannot spot it, because the page is the real page, on the real shop, at the real address, and nothing on your PC gets a look in. What actually helps is unglamorous: transaction alerts switched on, a virtual or single-use card number if your bank offers one, and a proper read of the statement each month. The automation misfired too. At one bicycle retailer an over-broad cleanup routine deleted 180 database tables, the administrator's backups among them. Tendvane's privacy and accounts check covers the half of this you do control, which is what sits saved and signed in on your own machine.

Sources

Download Tendvane