Hackers now steal AI access, not just data
Hackers are increasingly stealing AI credentials, such as API keys and session tokens, to hijack paid computing power and resell access, shifting focus from data theft to access theft. This emerging criminal economy targets AI services directly, exploiting corporate accounts for financial gain. Stolen credentials provide attackers with loot, compute, and cover, allowing them to run workloads at the victim's expense or hide malicious activity behind legitimate accounts. Anthropic and CrowdStrike report campaigns generating hundreds of thousands of API requests, with credentials harvested from code repositories, apps, and developer tools. The theft is industrialised, with criminals using automated pipelines to extract secrets from software and targeting users with fake AI tools. AI agents and supply chain integrations expand attack surfaces, prompting experts to urge enterprises to treat AI credentials as privileged access and comply with governance frameworks.