METR (Model Evaluation and Threat Research), a non-profit focused on AI safety, has disclosed two significant security incidents that occurred earlier this year. The first, in March 2026, involved the theft of an API key that was subsequently used by a financially motivated actor to rack up approximately $600,000 in fraudulent charges for AI model inference. The second incident, in May 2026, was a sustained, automated attack campaign targeting METR's public infrastructure. While METR states no sensitive information was accessed, these events underscore the high value of AI resources and the increasing targeting of AI research organizations by threat actors.
METR detailed two distinct attacks that highlight different threat vectors against AI organizations:
Incident 1 (March 2026): API Key Theft An attacker gained access to an API key used for inference on public AI models. This key was then abused to consume a massive amount of cloud computing resources, resulting in a financial loss of about $600,000. This type of attack, known as cryptojacking or resource hijacking, is purely financially motivated and exploits the high cost of AI computation.
Incident 2 (May 2026): Sustained Probing Campaign This was a more sophisticated, multi-faceted attack involving automated agents. The campaign included:
During this period, METR also discovered an unrelated, inadvertent exposure of a read-only SQL query mechanism that could have potentially leaked unpublished evaluation data.
The incidents demonstrate a range of TTPs targeting AI infrastructure:
T1528 - Steal Application Access Token. The key was likely exfiltrated from a misconfigured server, public code repository, or a compromised developer machine.T1595 - Active Scanning to probe for weaknesses in real-time.T1110.003 - Password Spraying or credential stuffing against login portals.T1566 - Phishing) shows a blended approach, combining technical and human-targeted attacks.M1017 - User Training.New details on METR's API key theft, including AI agent interaction and SSH persistence, clarify financial impact and highlight attacker use of AI agents.
Use secure vaults and secrets management systems to protect API keys and other credentials from theft.
Enforce MFA on all accounts to mitigate the risk of credential stuffing and password-based attacks.
Train employees to identify and report phishing attempts targeting them and the organization.
An attacker steals a METR API key and begins consuming AI credits.
A sustained, automated attack campaign begins probing METR's public infrastructure.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.