ZeroHour
Dark Readingpublished ()ingested Alexander Culafi

AI Model Evaluator METR Hit by Credential Theft, Probing

mediumData breach exploited in the wildimportance 55
AI summary · glm-5.3-flash

Threat actors stole an API key from AI evaluator METR and consumed $600,000 in public model credits; a second campaign probed its infrastructure.

Dark Reading reports that AI model evaluation nonprofit METR suffered a credential theft in which attackers obtained an API key that led to consumption of $600,000 worth of public AI model inference credits. METR also faced a separate sustained campaign in which financially motivated actors probed its publicly accessible infrastructure and attempted initial access via credential stuffing and OAuth token grants. No evidence of access to sensitive information was reported in either incident.

  • Stolen API key led to $600,000 in consumed public-model credits
  • Second campaign involved systematic probing and agent-assisted intrusion attempts
  • No confirmed access to sensitive or non-public data
VictimsMETR
OrganizationsMETR
Full article

In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.