Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
A human ransomware attacker used frontier AI models and agentic attack frameworks to breach an enterprise network in under 10 hours — a task that normally takes human operators around two weeks AI agents autonomously handled every attack phase: reconnaissance, internal microservice mapping, credential theft from code repositories, and pivoting across cloud, identity, CI/CD, and SaaS environments The attacker hijacked CI/CD workflows to steal cloud access keys and repurpose the victim's cloud AI
Analysis
TL;DR
- A human ransomware attacker used frontier AI models and agentic attack frameworks to breach an enterprise network in under 10 hours — a task that normally takes human operators around two weeks
- AI agents autonomously handled every attack phase: reconnaissance, internal microservice mapping, credential theft from code repositories, and pivoting across cloud, identity, CI/CD, and SaaS environments
- The attacker hijacked CI/CD workflows to steal cloud access keys and repurpose the victim's cloud AI services as post-compromise infrastructure, hiding orchestration traffic among legitimate activity
- After completion, an AI agent left an 80-page security audit detailing dozens of exploited findings as a taunt to the victim
- Palo Alto Networks' Unit 42 recommends defenders deploy AI agents with automated playbooks to revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines, and isolate cloud accounts in response
Why It Matters
This incident represents a paradigm shift in cyberattacks — demonstrating that frontier AI models can dramatically compress attack timelines without requiring novel zero-days or elite tradecraft, making sophisticated intrusions accessible to a broader class of threat actors. For AI practitioners and security teams, it underscores the urgent need to treat AI infrastructure (model endpoints, API keys, MCP gateways) with the same rigor as traditional IT assets, and to deploy AI-powered defensive agents capable of matching machine-speed attacks.
Technical Details
- Attack architecture: The attacker employed a multi-agent framework where specialized subagents performed distinct roles — reconnaissance agents mapped internal microservices, scraping agents extracted hard-coded tokens and service passwords from code repositories, and "specialist pivot agents" validated access across cloud, identity, CI/CD, container, and SaaS environments
- Credential chain exploitation: Hard-coded tokens stolen from code repos were used to access the organization's secret-management system, yielding master administrative credentials and root system access
- Infrastructure hijacking: CI/CD workflows were compromised to steal cloud access keys, and the victim's own cloud AI services were turned into post-compromise infrastructure, with orchestration traffic masked among legitimate activity
- Autonomous operation: AI agents monitored, evaluated, acted, and re-planned in real time throughout the attack chain, requiring minimal human intervention after initial setup
- Defensive recommendations: Unit 42 advocates for automated defensive playbooks that simultaneously revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines, and isolate cloud accounts across all operational planes, plus comprehensive inventory of all model endpoints, API keys, and AI tool integrations with rate limits and least-privilege policies
Industry Insight
- The democratization of offensive AI capabilities means security teams must assume attackers can execute complex, multi-stage intrusions at machine speed — defensive strategies based on traditional human-paced threat models are now insufficient
- Organizations should conduct an immediate audit of all AI-related infrastructure (model endpoints, API keys, MCP gateways, agent integrations) and enforce strict least-privilege access and rate limiting to prevent credential theft and unexpected token bills from compromised agents
- The arms race between offensive and defensive AI agents is inevitable; companies that fail to deploy AI-powered automated response capabilities will face a growing gap in their ability to detect and contain machine-speed attacks
Disclaimer: The above content is generated by AI and is for reference only.