[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkfRNW6IyUJYVGLnDqH-ooJwuKnkKH4erYe2uYqGpK3w":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"0156ac4b-f404-4c7a-9e34-49bf029d19e7","api-key-theft-costs-ai-nonprofit-600k-in-misused-cloud-credits","98ea6c42-17be-43c7-95ca-5fe2ef886077","API Key Theft Costs AI Nonprofit $600K in Misused Cloud Credits","METR suffered a significant financial loss after threat actors stole an API key and used it to consume approximately $600,000 worth of AI model credits. The root cause lies in inadequate access control practices around API key lifecycle management, including likely insufficient monitoring of key usage patterns that could have detected anomalous consumption early. API keys are high-value credentials that, unlike passwords, are often long-lived, broadly scoped, and embedded in code or configurations where they are easily exposed. This incident underscores that credential compromise can cause direct financial harm beyond data breaches, and that API keys must be treated with the same rigor as privileged account credentials.","**Immediate actions:**\n- Rotate and revoke all exposed or suspected API keys immediately, issuing new scoped replacements with least-privilege permissions.\n- Enable real-time usage alerts and spending thresholds on all cloud and AI platform accounts to detect abnormal credit consumption.\n\n**Long-term improvements:**\n- Implement secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager) to centrally store, rotate, and audit all API keys.\n- Enforce short-lived, automatically expiring API tokens with narrowly scoped permissions tied to specific services or functions.\n- Conduct regular audits of all issued API keys to identify orphaned, over-privileged, or long-lived credentials and decommission them.\n\n**Detection measures:**\n- Deploy behavioral anomaly detection on API usage to flag sudden spikes in credit consumption or requests from unexpected IP ranges.\n- Establish a Security Information and Event Management (SIEM) pipeline that ingests API gateway logs and triggers alerts on policy violations.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 5 – Account Management","CIS Control 8 – Audit Log Management","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","NIST SP 800-53 IA-5 (Authenticator Management)","NIST SP 800-53 AU-6 (Audit Record Review, Analysis, and Reporting)","NIST CSF DE.CM-1 (Continuous Monitoring)","OWASP API Security Top 10 – API2: Broken Authentication","GDPR Article 32 – Security of Processing (where personal data may be involved)","published","2026-09-01T22:21:47.334279+00:00","2026-09-01T22:21:47.239+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.darkreading.com\u002Fidentity-access-management-security\u002Fai-model-evaluator-metr-credential-theft-probing","ai-model-evaluator-metr-hit-by-credential-theft-probing-19d1bd","AI Model Evaluator METR Hit by Credential Theft, Probing",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]