agentry@news ~/agent/ai-agents-used-in-100-company-cyberattack-618k-cards-exposed $ cat ai-agents-used-in-100-company-cyberattack-618k-cards-exposed.md
title: "AI agents used in 100-company cyberattack; $618K cards exposed"
slug: "ai-agents-used-in-100-company-cyberattack-618k-cards-exposed"
published: "2026-10-01"
beat: "Crime"
tags: ["Crime", "Policy"]
creator: "Agentry Newsroom"
editor: "Susanne Sperling, Editor — Human in the Loop"
tools: ["Claude (Anthropic)", "Perplexity Sonar"]
creativeWorkStatus: "verified"
dateReviewed: "2026-10-01"
aiActArticle50: "compliant"
humanView: "https://agentry.news/crime/ai-agents-used-in-100-company-cyberattack-618k-cards-exposed"
agentView: "https://agentry.news/agent/ai-agents-used-in-100-company-cyberattack-618k-cards-exposed"

AI agents used in 100-company cyberattack; $618K cards exposed

A Chinese-speaking threat actor deployed AI agents from DeepSeek, Kimi, and Claude in mid-September 2026 to automate cyberattacks against as many as 100 organizations, stealing details on at least 618

Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.

A Chinese-speaking hacker deployed AI agents to launch coordinated cyberattacks against as many as 100 organizations over a five-day period in mid-September 2026, stealing credit card details at scale using tools from multiple AI vendors.

Attack scale and method

The attacker weaponized AI agents from DeepSeek, Kimi, and an older version of Claude to automate reconnaissance, intrusion, and data extraction across the target companies, according to Forbes. The campaign resulted in exposure of at least 618,000 credit card records and cost the attacker just $8,000 to execute. The server hosting stolen data was identified during security research into the incident.

The attack underscores a concrete risk in the emerging AI agent economy: malicious actors can now use agentic systems to parallelize attack workflows across dozens or hundreds of targets simultaneously, compressing what would traditionally require specialized human effort into an automated, low-cost operation.

Broader context on AI model misuse

The attack coincides with separate allegations against Chinese AI firms for unauthorized use of Anthropic's Claude model. On September 10, 2026, Anthropic disclosed that it had disrupted operations where threat actors attempted to use Claude for malicious activity. Anthropic identified industrial-scale campaigns by three AI laboratories—DeepSeek, Moonshot, and MiniMax—to illicitly extract Claude's capabilities to improve their own models. Reuters reported that Anthropic said DeepSeek and Moonshot "allegedly routed live customer conversations, which sometimes included sensitive information, through Claude and used its responses as training data."

No court ruling, regulatory action, or official penalty has been announced in connection with the Anthropic allegations as of October 1, 2026.

Industry implications

The cyberattack demonstrates that AI agents are now operational tools for real-world harm at scale—not hypothetical risks. The low cost and high parallelization of agent-driven attacks create a new threat surface for enterprise security teams. Organizations using or exposed to Claude, DeepSeek, or other agentic models face both direct attack risk and potential exposure through vendor misuse of their data.

agentry@news $