A Growing Threat: How AI Gateways Can Expose Organizations to New Risks
As organizations increasingly rely on artificial intelligence (AI) to power their applications and workflows, they’re also creating new vulnerabilities that threat actors are all too eager to exploit. A recent incident highlights the risks associated with AI gateways, which can provide attackers with a treasure trove of sensitive data, including access to AI models, cloud infrastructure, and identity and access management (IAM) information.
The incident in question involved an attacker gaining access to an Amazon Web Services (AWS) EC2 server hosting an AI gateway connected to Amazon Bedrock services. While the attacker used the access for cryptomining, they could have easily abused the AI gateway to access connected models and data, manipulate AI workflows, or pivot deeper into the organization’s cloud environment. According to Nathaniel Jones, vice president of security and AI strategy at Darktrace, this incident is “the tip of the iceberg” – a warning sign that AI gateways are becoming attractive targets for attackers.
One reason why AI gateways are so appealing to threat actors is their ability to aggregate capabilities from separate systems. They typically have centralized access to multiple AI providers, high-value API credentials, and enterprise identity integration access to internal documents and knowledge. “Think of them as a mini supply chain,” Jones says. “An attacker can use the gateway as a single point of entry to access sensitive data and systems, making it much easier for them to move laterally within the organization’s cloud environment.”
The risks associated with AI gateways are not limited to credential theft or data access. Attackers could also leverage IAM roles to pivot into broader AWS resources, generate significant financial impact through abuse of AI inference services, or establish persistence within the cloud environment. In other words, while cryptomining may have been the payload in this case, the initial access technique could be reused by more sophisticated actors with very different objectives.
For organizations racing to AI-enable their applications and workflows, the incident is another reminder that every new AI component in the environment can expand the attack surface. As Jones notes, “The risks include those tied to AI models themselves, such as model poisoning and prompt injection; vulnerabilities and weaknesses in AI infrastructure, including Model Context Protocol (MCP) servers and AI gateways; insecure use of coding agents, and agentic AI more generally.”
So what can organizations do to mitigate these risks? The key takeaway is not what actually happened, but what could have easily transpired if the attacker decided to leverage the AI gateway. As Jones warns, “While cryptomining is noisy and relatively easy to detect, credential theft and cloud persistence would have been far more concerning outcomes.” To stay ahead of the threat, organizations must prioritize security and implement robust access controls, monitoring, and incident response plans specifically designed for AI gateways. By doing so, they can minimize the risks associated with these critical systems and protect their sensitive data from falling into the wrong hands.
Source: Dark Reading — 2026-07-09