Cyber Threat Intelligence, Entrepreneur, Presentation Virtuoso

Four Dollars Is All the AI Costs to Break Into Your Company

An affiliate of The Gentlemen ran an automated AI pipeline that broke into 30-plus companies, stole 3.1TB, and wrote the ransom demands itself. The AI cost per victim was as little as 40 cents. That is not the whole operation, but it is the part that used to take a skilled human days.
Four Dollars Is All the AI Costs to Break Into Your Company

the entire ai cost of breaking into a target, stealing data, and building a ransom demand can cost as little as US$0.40 and as much as US$4 per victim! not US$4000. four. fscking. dollars! at the high end. that is what it costs for ai to do the work, and it is an important figure in ecrime right now.

cybernews found an exposed server belonging to an affiliate of the gentlemen, the russian-speaking ransomware crew i previously wrote about. this is the adversary poaching affiliate talent with 90% splits.

this is what that talent is now building. on the server, 3.1TB of data stolen from more than 30 companies, healthcare, software, consulting, manufacturing, telecom. the entire operation is largely being run through an automated ai pipeline. no surprises considering the era we live in nowadays.

the stack was not theoretical either. cybernews found the hermes agent using deepseek v4 pro, connected through an mcp interface to live reverse shells, with 86 ai-generated python scripts already tailored to real victim environments.

to be abundantly clear, the US$4 figure is the cost of ai tokens per company. it does not count the servers, the infrastructure, and the other operational costs of the operation. the total cost to conduct a full-fledged ransomware attack is absolutely not US$4. it is US$4 for the piece that previously required a skilled human operator spending days to get the work done. this is what has collapsed, and that matters.

how does it work? the human does remarkably little. they point the ai at a gitlab target, hand it valid working credentials, and tell it to get to work.

and here is one of the stranger details. the operator reportedly wrapped the intrusion in an alice in wonderland-themed capture-the-flag story. this effectively told the model it was solving a security challenge instead of breaking into real companies. even escaping the guardrails became part of the workflow.

the agent conducts reconnaissance against the target environment, and adapts its scripts accordingly. it then steals the source code and the data, and moves on to the next target. an assembly line, not a heist.

is this a henry ford of ai ecrime moment? some new innovation to make ecrime even more dangerous, less expensive, more efficient?

after the theft, ai reads through everything it stole and does the analysis a human extortionist used to do by hand. it estimates how much a given victim can potentially afford to pay, based on their revenue and the value of what was stolen. it writes the ransom demand, tailored to the specific company.

it even evaluates how the stolen data can be monetized. extort them directly, auction the data, sell the source code to a competitor, or turn around and phish the victim's own customers. the machine does not just do the crime. it does the business strategy too.

consider what that means for ecrime economics. for as long as ransomware has existed, there was a natural limit on it. human attention is finite. a skilled operator could only work so many targets at once, because each one took real time and real expertise.

i have been beating the drum that this limit has disappeared. when the marginal ai cost of targeting one more company is measured in cents to a few dollars, there is far less economic reason to be selective. you do not pick only high-value targets anymore. you attack everyone, and let the ai sort out which ones are worth extorting.

that is the shift, and it is not coming, it is running on an exposed server right now. ecrime that used to be heavily constrained by skilled human operators is now able to shed one of its biggest bottlenecks.

the barrier protecting small and mid-sized companies, that they were not worth a skilled attacker's time, has effectively disappeared.

you were never too small to hack. you were only ever too small for the adversary to care. but ai does not get bored, it works for a pittance, never sleeps, does not need a vacation, and is not interested in maternity leave.