Governance & Risk
At $25 a target, your company is worth hacking now
AI agents cut the cost of an attack to about $25 a target, and they go in through the systems nobody watches. The five numbers your board should see this quarter.
Satori Canton
October 7, 2026 · 10 min read
In late August, an attacker pasted a list of 301 online stores into an AI agent and told it to find a way in. The agent scanned them, chose what to exploit, and handed off to other agents that did the exploiting. By mid-September at least 27 companies had been compromised, and the attacker's own records put the average cost of a completed scan at $25.46, according to Gambit Security, which recovered the operator's staging server.
The stores were not chosen because they were valuable. They were chosen because they were on a traffic-ranking list and ran custom code. Gambit's summary of what that means is the sentence every mid-size company should read twice: "the economics no longer filters anyone out."
For most of the history of corporate security, economics was the filter. A capable attacker's time was expensive, so it went where the money was: banks, large retailers, governments. A regional insurer, a specialty manufacturer or a hospital group could reasonably assume it was not worth the effort of a skilled team. That assumption was never a security control, but it worked like one.
At $25 a target, it no longer works.
The price of an attack, in 2026
The fall did not happen all at once. It is visible in a run of measurements, most of them from the people building the models.
| When | What was measured | Cost or speed | Source |
|---|---|---|---|
| April 2024 | A GPT-4 agent given a vulnerability's public description exploited 87% of 15 known flaws in a test | $8.80 per exploit, against $25 for a human | University of Illinois researchers |
| November 2025 | A state-sponsored group ran an espionage campaign against about 30 targets in which AI did 80 to 90% of the work | Thousands of requests, often several per second | Anthropic |
| June 2026 | A frontier model turned published Windows patches into working privilege escalation exploits | About $2,000 per escalation | Anthropic |
| September 2026 | An attacker's agents scanned and attacked online retailers, compromising at least 27 | $25.46 per completed scan, on average | Gambit Security |
| September 2026 | A small, freely downloadable model chained two known Chrome flaws into a working exploit, in a lab | $20.40, with 20 minutes of human attention | Anthropic |
| October 2026 | Microsoft's annual threat report measured how fast newly discovered flaws are turned into working attacks | Median well under 24 hours | Help Net Security, on the Microsoft Digital Defense Report |
Two cautions keep this honest. Every one of these operations still had a human in it: the retail campaign's operator typed nearly 2,000 prompts, and Microsoft notes that choosing targets and running complex intrusions is still mostly manual work. And the lab results are lab results. But the direction is not in dispute, and the U.S. government has already acted on it. In June, CISA replaced its patching directive for federal agencies with BOD 26-04, citing AI's potential to "further narrow the time defenders have to react," and cut the deadline for the most serious exposed flaws to three days.
The useful way to read the table is not "AI hackers are coming." It is that the cost of looking at your company has fallen to roughly the cost of lunch, and anything that is cheap to look at gets looked at.
The cheap attack goes in through the side door
When an attack costs little, the attacker no longer needs the front door. It can try every door, and the doors that open are the ones nobody has been watching.
That is what happened in South Korea last week. Seven financial firms, including Shinhan Bank, KB Kookmin Bank and Hana Bank, reported breaches exposing data on more than 67,000 people, the Korea Times reported. Investigators traced the attacks to ARTEX AI, an open source penetration-testing agent, run by a human operator. Every attack hit an internal system built for employees or partners rather than customer banking, The Herald Business found: a loan-agent inquiry service at Shinhan, an employee mobile work system at KB Kookmin, an employee sales system at Hana. The three largest banks had spent about $92 million on information security the year before. The money protected what it was pointed at.
An official at Korea's Financial Security Institute put the problem plainly: there were so many management points across such a wide scope that the banks themselves had trouble finding where the weaknesses were. The institute is now drafting a recommendation that financial firms audit every employee-facing system reachable from outside.
Korea is not unusual. It is early. Look at where else the cheap attack has gone in the past month.
- Your partners' systems. Third parties were involved in 48% of breaches in Verizon's 2026 Data Breach Investigations Report, up 60% in a year, and only 23% of third parties had fully fixed missing or weak multifactor login on their cloud accounts.
- Your employees' own accounts. AI coding agents published more than 13,000 internal screenshots to public GitHub repositories, and 93% of them sat under employees' personal usernames, where a company's own audit would not look, Glow found.
- Your public forms. A single lead submitted through Salesforce's public Web-to-Lead form could carry instructions that made Agentforce read and leak CRM account data when an employee asked it to review leads, Zenity Labs showed. Salesforce fixed it in August. The pattern, a stranger's text reaching an agent with internal access, is everywhere.
None of these systems is a crown jewel. That is the point. A security budget sorted by business importance protects the systems an attacker would choose if attacking were expensive.
Your patch window is now the attacker's window
The second thing that breaks at $25 a target is time.
The 2026 Verizon report found that organizations fully fixed only 26% of vulnerabilities on CISA's list of flaws known to be exploited, and took a median of 43 days to do it. Mandiant's M-Trends 2026 estimates that, on average, exploitation now begins about a week before a patch is even available. Microsoft measures the gap between discovery and a working attack in hours.
A 43-day patch cycle made sense when exploiting a flaw took a skilled team weeks. It does not make sense when an agent can write the exploit overnight for the price of a sandwich. That is why CISA rebuilt its federal deadlines around exposure rather than severity alone: under BOD 26-04, a flaw on an internet-facing system that is already being exploited and gives an attacker full control gets three days, plus forensic triage to check whether the system was already compromised. Taking the system off the internet buys more time. Leaving it exposed does not.
The directive binds only federal agencies. It is still the best published benchmark for what "fast enough" now means, and a board can ask how far its own company is from it.
Watch what leaves
The third change is in what an attack looks like on the network.
In September, Cisco Talos described CLOSEDQUORUM, a Windows implant that asks up to four commercial AI services, DeepSeek, Qwen, Mistral and Gemini, what to do next, and takes the majority answer. Talos has not confirmed it in the wild. But it shows where the control channel of an AI-driven attack lives: in ordinary encrypted traffic to the same AI providers your own staff use every day.
That makes outbound traffic, not inbound, the place to look. Talos's advice is to watch for AI API traffic coming from a program that has no business making it, several AI providers called in quick succession, and data leaving to services such as chat webhooks. Most companies cannot do that today, because they have never written down which of their own systems are supposed to talk to which AI services. Without that list, a compromised server asking a model for its next move looks like everyone else's Tuesday.
Defenders get the same tools, with conditions
None of this is one-sided. Google has released Gemini 4 Argon to vetted defenders and plans a version without cyber guardrails for them, The Hacker News reported, and the same agents that probe a retailer for $25 can probe your own perimeter for less. Running them against yourself first is the cheapest red team you will ever buy.
Two cautions from the past week. Google paused part of its open source bug bounty on October 1 after a flood of automated reports, most of them invalid, Help Net Security reported, so AI makes defenders' triage cost go up too. And in Korea, regulators had been relaxing the rule that keeps bank systems off outside networks so that banks could run AI security tools. After the breaches, the Financial Services Commission postponed choosing the next group of firms, while saying the policy itself continues. If you open a control to let AI in, decide in advance who watches it and what closes it again.
This article is the argument. The method is in The $25 Attacker: Find Your Weakest Door Before an AI Agent Does, a research paper with an exposure register you can adopt as written, a scoring rubric that ranks every externally reachable system by how easily it opens, patch clocks keyed to CISA's new deadlines, an egress checklist for AI-driven command traffic, contract terms for contractors and partners, and a one-page board briefing. Read the executive summary, which is free.
What to do this quarter
The work is unglamorous, and most of it is counting. It needs three owners.
For the CISO. List every system reachable from outside your network, including the ones contractors, partners and business units set up, and rank them by how strong their login is, not by how important the business says they are. Anything still on a password alone, or a shared account, goes to the top. Then measure your real time to patch an exploited flaw on an exposed system, and compare it with CISA's three days.
For the chief AI officer. Write down which systems are allowed to call which AI services. That list is what makes an unexpected caller visible. And for every control you relax to deploy AI, name an owner and a written condition for rolling it back.
For General Counsel. Put minimum login standards, a duty to tell you their external addresses, and a breach notification window into contractor and partner agreements at renewal. If you are a U.S. public company, your annual report already has to say whether you have processes to oversee risk from third-party service providers. Make sure the answer is true of the portals.
Then take five numbers to the board: how many systems you expose, how many of them still accept a password alone, your median days to patch an exploited flaw on one of them, how much of your outbound traffic you can attribute to a known system, and how long the last intrusion on a low-tier system went unnoticed. A company that can answer those five is not out of reach of a $25 attacker. It is just no longer the cheapest one on the list.
Satori Canton
Founder & Principal
Satori Canton is the founder and principal of ROAI, an advisory practice focused on measuring and improving the return on enterprise AI investment.
Related insights
Ask AI vendors for lists, not assurances
Third parties were involved in 48 percent of breaches this year. The standard AI vendor questionnaire now runs to 247 controls and still misses what went wrong.
September 8, 2026 · 15 min read
Governance & RiskThe ML tools your data team installed are on CISA's exploited list
CISA added four AI platform tools to its actively exploited catalog this year. The warning time ranged from 264 days down to none at all.
August 24, 2026 · 10 min read

