The "carding" technique, which involves stealing credit card information, continues to be a threat in the digital age, and recent reports show it has evolved with the use of artificial intelligence (AI) tools. According to a report by the security company Gambit, a campaign using three open-source AI tools could have allowed a malicious actor to exploit vulnerabilities in at least 27 companies and steal over 600,000 credit card identifiers, with an estimated total value of $15 million. The attack relied on three distinct AI agents, each performing specific roles in the campaign. The first agent, Strix, is an open-source tool designed for penetration testing, which was used to identify weaknesses in the targeted systems. It operated using the GLM 5.2 model from Z.ai, then switched to the DeepSeek V4 Pro model. The second agent, Cairn, is an autonomous tool capable of conducting full-scale attacks. It ran on the DeepSeek 4.1 Flash model. The third agent, Hermes, coordinated the entire campaign and executed direct attacks using the Claude Opus 4.6 model from Anthropic. This agent had 121 skills, 78 of which were offensive in nature. All the AI models were accessed through the OpenRouter platform, which provides access to various AI tools. According to Eyal Sela, director of threat intelligence at Gambit, the human operator only needed to provide 1,951 instructions across 260 sessions, indicating minimal direct involvement. Once access was obtained, it typically took less than a day, and in some cases, only a few hours. The operator’s OpenRouter account incurred costs of $7,005.71 over four weeks, with the total estimated cost of the campaign ranging from $12,000 to $18,000. The average cost of a full scan was about $25.46, with variations depending on the target. The campaign began in July and reached its peak between September 10 and 15, during which the operator launched 105 attack projects and compromised at least 27 companies. Gambit confirmed the presence of skimmers—malicious scripts that collect payment data—in 19 of the identified victims and detected similar skimmers on more than 100 other websites. The affected companies spanned various sectors, including the hotel industry, a major American airline, a private industrial distributor, and an online fashion site, all based in the United States. The 600,000 card records came from two companies, and 79% of the cardholders involved were American. The skimmers were hidden in common JavaScript libraries such as jQuery and in Google tags. On the website of an American wine reseller, an automated task reinstalled the skimmer every two minutes after each site reset, causing significant frustration for developers. Gambit has informed several affected organizations and helped dismantle the attack infrastructure with support from the Shadowserver Foundation, a group that tracks and removes malicious content online. The company Overwatch Data is responsible for notifying card issuers such as Visa, MasterCard, and American Express. The report highlights that AI agents can indeed be exploited for malicious purposes by anyone with access to them. Even the major AI companies sometimes struggle to keep their models fully contained during training, which can lead to accidental breaches, even during routine exercises.