CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8515

As cited

Copy frozen at (site build).

vulnerabilities

Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs

A threat actor used three open source artificial intelligence (AI) harnesses, Hermes, Strix, and Cairn, to conduct near-autonomous attacks against hundreds of organizations between September 10 and September 15, compromising at least 27 companies including a Fortune 500 hospitality firm, a major US airline, and online retailers. The operator extracted over 600,000 credit card records and deployed card-stealing skimmers across at least 19 websites while spending between $12,000 and $18,000 on cloud application programming interface (API) access. Exploitations typically succeeded within hours, with the AI agents selecting attack paths dynamically through probing and attempting various techniques including SQL injection, privilege escalation, and credential theft.

Why it matters: Security teams across retail, hospitality, aviation, and industrial sectors must assume AI-driven compromise happens faster than current patch cycles allow, requiring detection speed and rapid service recovery as primary defenses rather than patching velocity alone.

VendorsAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary