AI Model Evaluator METR Hit by Credential Theft, Probing

Cybersecurity Nonprofit METR Hit by Credential Theft and Probing Attacks

A security nonprofit that helps evaluate risks in frontier AI models has disclosed two cybersecurity incidents, including a breach that exposed an API key and resulted in over $600,000 in unauthorized credits being consumed. The attacks highlight the growing threat of credential theft and probing attempts on organizations handling sensitive data.

METR (Model Evaluation and Threat Research) is a non-profit organization that helps evaluate risks in frontier AI models. In March, attackers stole an API key used for inference on public models, allowing them to consume a substantial number of credits without METR’s knowledge. The attack was successful because the company had inadvertently exposed an AWS EC2 instance with the API key, which was then harvested by the attacker using publicly available tools.

The attacker used the stolen credentials to establish persistence on a system and spent three weeks consuming API credits on publicly available AI models. The incident highlights the importance of protecting sensitive data, such as API keys, from unauthorized access. METR has since increased its security investment in response to the attack, including hiring a security lead, shutting down legacy infrastructure, conducting regular threat modeling reviews, and deploying additional endpoint and server security software.

The May incident involved probing attempts on publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. METR described this as a “sustained external attack campaign” that may have been motivated by financial gain or access to advanced AI models. During the campaign, attackers used agents to automate reconnaissance and vulnerability discovery, including credential stuffing, OAuth-related attacks, scanning for newly deployed services, and phishing attempts.

The two incidents demonstrate the growing threat of probing attacks on organizations handling sensitive data. Probing attacks involve testing vulnerabilities in an organization’s systems to identify weaknesses that can be exploited later. The use of agents to automate reconnaissance and vulnerability discovery makes it difficult for organizations to detect these types of attacks.

METR classifies company data into four categories: previously published information, unpublished evaluation results involving public models, sensitive model access, and highly sensitive information, including intellectual property and business data. The May incident involved an inadvertently exposed read-only SQL query mechanism via a public transcript viewer that could have been chained with a bug to access unpublished evaluation data.

The attacks on METR highlight the importance of protecting sensitive data from unauthorized access. Organizations handling AI model data should prioritize securing their API keys, conducting regular threat modeling reviews, and deploying additional endpoint and server security software. Furthermore, organizations should be cautious when exposing publicly accessible infrastructure and ensure that all endpoints are properly secured to prevent probing attempts.

In light of these incidents, readers should take note of the following best practices: regularly review and update API key management policies, conduct thorough risk assessments on sensitive data, and implement robust monitoring and alerting systems to detect suspicious activity. By taking proactive measures to secure their infrastructure and data, organizations can reduce the risk of falling victim to probing attacks and credential theft.


Source: Dark Reading — 2026-09-01