AI credentials are becoming targets for cybercriminals This article explores ai credentials targets. . A new tactic called AI token jacking allows attackers to steal API keys and use them to consume expensive model services on someone else’s account.

The theft isn’t limited to a single method; it can occur through phishing, malware, exposed file shares, public code repositories, or poisoned software packages. Unit 42 analysts identified an increase in these incidents and reported that attackers have exploited inadvertently exposed credentials for nearly $1 million in charges before victims detected the abuse. AI providers often bill after usage rather than stopping every unusual request in real time, while accounts can scale without limits. Stolen keys thus represent ready-made purchasing power, not just a password.

Organizations should establish AI spending caps, generate alerts when usage exceeds the baseline, and review every privileged account capable of provisioning resources or changing billing controls. Indicators of compromise (IoCs): - User-Agent: Go-http-client/2.0,gzip(gfe) associated with malicious API calls - IP addresses: 3.235.109[. ]125, 116.105.166[.

]148, 172.96.142[. ]186, etc., all involved in malicious API calls - IP addresses: 38.46.219[. ]166, 38.46.219[. ]163, 38.46.219[.

]162, 23.237.196[. ]170, etc., involved in malicious API calls - IP addresses: 15.204.106[. ]173, 104.243.42[. ]117, 198.255.70[.

]210, etc., all related to malicious login and credential theft - Domain: amutes[. ]com, abb1[. ]life, transfer station infrastructure - Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking.