TheVortiq
Inteligencia Artificial

AI Cyberattacks: The End of Traditional Cybersecurity

The emergence of autonomous agents like Strix, Cairn, and Hermes marks a paradigm shift in the cost and scale of global cybercrime.

September 29, 2026 · 4 min read

a black and blue abstract background with squares and rectangles

TL;DR: A new generation of autonomous AI agents allows for large-scale cyberattacks for just $25 per target. This shift drastically lowers the barriers to entry for cybercrime, automating data theft and operational disruption.

The democratization of large-scale cybercrime

Since July 2026, the cybersecurity ecosystem has experienced a tectonic fracture. Researchers at the firm Gambit have documented a massive attack campaign, powered by autonomous artificial intelligence agents, that has managed to breach hundreds of websites and extract more than 600,000 payment card records. This event does not represent a simple evolution in criminal modus operandi; it marks the beginning of an era where the scale of an attack is no longer limited by human capacity, but by the availability of computing power and the efficiency of language models.

Unlike traditional ransomware attacks, which usually required a manual reconnaissance phase or the purchase of initial access on dark markets, this campaign operates under an "attack-as-an-automated-service" logic. The ability to infiltrate complex infrastructures, such as those of a Fortune 500 company or a major U.S. airline, at a negligible cost, alters the business model of cybercrime: it is no longer about a high-profile masterstroke, but a profitable massification of low-intensity intrusions that, together, generate a devastating economic impact.

The automation trident: Strix, Cairn, and Hermes

The core of this operation lies in three autonomous frameworks or harnesses: Strix, Cairn, and Hermes. The architecture of these agents allows for operational autonomy that was previously theoretical. Hermes, the most sophisticated component, stands out for its persistent memory capability, which allows it to self-edit its attack scripts in real-time after analyzing the victim's defenses. According to technical reports, these agents use models like Anthropic opus-4.6 to orchestrate the intrusion, selecting targets through web classification services and prioritizing platforms with custom software, which often present unique vulnerabilities not covered by standard protections of traditional content management systems (CMS).

The operation is relentless. Between September 10 and 15, 2026, these agents executed 105 waves of attacks, compromising 27 organizations in just five days. This speed suggests that human intervention in the attack chain has been reduced to the initial configuration phase and the management of command and control (C2) infrastructure, leaving the dirty work—scanning, exploitation, and exfiltration—entirely in the hands of AI.

Economic efficiency: The $25 attack

Historically, cybercrime was a human-capital-intensive activity, where profitability was subject to the attackers' ability to scale their operations without being detected. This campaign has demonstrated that the cost of compromising an organization has been reduced to an average of $25.46 per target. Over a four-week period, the attackers invested approximately $7,000 to orchestrate a campaign that spanned from large fashion retailers to industrial distributors.

This cost marginality allows threat actors—allegedly linked to financial groups in China—to attack ten companies a day persistently. We are facing a disturbing historical comparison: if in the 2010s the cost of a successful attack depended on the attacker's skill and time invested, today the cost is an infrastructure variable, comparable to purchasing API subscriptions. The barrier to entry for elite cybercrime has collapsed.

Impact and consequences: Why should we be concerned?

The use of autonomous agents removes the human bottleneck, allowing the attacker to scale their activity to industrial levels. These systems do not just execute attacks; they learn from every mistake, adapt their entry vectors, and manage their own infrastructure. The ability of these agents to perform data cleanup tasks after exfiltration has resulted, in several cases, in the total operational disruption of the victims, exacerbating the financial damage with operational recovery costs that exceed the value of the stolen data by orders of magnitude.

The fact that Fortune 500 companies and top-tier airlines have been breached confirms that traditional perimeter defenses are insufficient. These incidents serve as a reminder that AI models, when used for malicious purposes, can outpace the reaction times of incident response teams (SOC). The immediacy of the machine versus the slowness of human analysis creates a power asymmetry that systematically favors the attacker.

Defense strategies for the new reality

For companies, the lesson is clear: static signature-based defenses have become obsolete. Faced with agents that can rewrite their attack code in real-time, the only response is a rigorous Zero Trust architecture, where every movement within the network is verified and authenticated. It is imperative to implement AI-based anomaly detection systems that do not look for virus 'signatures', but monitor network behaviors and access patterns that reveal the presence of autonomous agents.

Continuous security auditing must replace annual reviews. Organizations must assume that the automation of the attack lifecycle—from reconnaissance to exfiltration—is already a reality. In this new scenario, resilience is not measured by the ability to avoid an attack, but by the speed of detection and the ability to segment the network to limit the blast radius of an automated intrusion. The era of reactive cybersecurity is over; the era of algorithmic defense begins.

Keep reading