A skimmer breached 100 companies because nothing in the response chain moved at machine speed.
A skimmer breached 100 companies because nothing in the response chain moved at machine speed.
According to new reporting from Forbes, a hacker spent about $8,000 and five days running agentic AI models against roughly 100 companies. Researchers at Gambit Security found the operation after the attacker left their own infrastructure exposed: over 618,000 stolen credit card numbers sitting next to the AI prompts that pulled them out. It's a striking number. It's also, if you read past the headline, not the story most people will assume it is.
What kind of breach was this, exactly?
This wasn't a database walking out the door. The attacker's agents, built on Claude Opus 4.6, DeepSeek's v4.1-flash and Moonshot's Kimi, orchestrated through open-source frameworks called Cairn and Hermes, probed each target for vulnerabilities, exploited trust relationships and installed a payment skimmer on the checkout flow. That skimmer captured card numbers as real customers typed them into real transactions, then sent the details straight to the attacker's own server. No one's card data was sitting in a file somewhere waiting to be discovered. It was intercepted at the moment it was created.
Would a data security program have stopped this?
No, and it's worth saying that plainly. A skimmer running on a public checkout page captures data before it ever reaches the channels a data security platform is built to watch: SaaS applications, managed endpoints, email, on-prem file shares, GenAI tools. This attack lived in the merchant's public web infrastructure. Stopping it is a job for vulnerability management, web application firewalls, content security policy and server hardening, not DLP, DSPM or IRM. Any vendor telling you differently is selling theater.
So what actually failed here?
The failure was speed. Investigators noted an unusual number of vectors dug up individually for every target, each attack custom fit to the company it hit. A one-person operation ran a customized, multi-vector campaign against a hundred organizations at once, for roughly the cost of a used car, and most of those organizations still don't know it happened. That's only possible because every step standing between "vulnerable" and "breached" (scanning, patch review, code review, alert triage) still assumes a person is the one who has to notice it and decide what happens next. The attacker's tooling never waited on any of that.
Why does the machine speed problem reach beyond this one breach?
The same bottleneck shows up everywhere in security programs, appsec included. A vulnerability sits in a backlog. An alert waits in a queue for someone with the right context to open it. A policy exception waits on approval. None of that is a flaw specific to any one tool category. It's what happens when a defense built around human review meets an offense that doesn't need any.
Inside the categories MIND does govern, data at rest and in motion across SaaS, endpoints, email and the GenAI and agentic tools now touching sensitive data, the same principle holds. MIND isn't claiming credit for stopping a checkout skimmer. What it's built to do is make sure the exposure it does watch gets handled at the pace it actually changes, not the pace someone gets around to reviewing it. The Issue Investigator Agent analyzes patterns as they emerge, the Rapid Response Agent acts without sitting in a queue and the Custom Classifier Agent keeps refining what counts as sensitive as the business changes. It's a narrower claim than "we'd have stopped this," and a truer one.
MIND became the first data security company accepted into Anthropic's Cyber Verification Program on that same premise: watching how AI gets used on both sides of the fight matters, and pretending a single platform covers every attack surface doesn't serve anyone.
This breach is a good prompt for a different question than "were we protected." Ask instead where in your own program a control is still waiting on a person to get to it, in DLP or anywhere else. If that answer makes you uneasy, it's worth seeing what MIND looks like running at machine speed in your own environment. See MIND in action.
Let's mind what matters.







