ASD is aware that malicious cyber actors are obtaining unauthorised access to organisations' AI services through compromised API keys, stolen authentication tokens, compromised user sessions, vulnerable applications and third-party access arrangements. This access can enable unauthorised usage to create harmful material, distill model capabilities, exhaust available credits and disrupt legitimate work.
Organisations should treat access to advanced AI services as a security-sensitive asset. Protecting that access requires more than relying on the AI developer's security controls. The organisation's accounts, devices, applications and third-party arrangements also need to be secured.
How organisations can reduce the risk
Assign ownership and apply least privilege
Maintain an inventory of AI accounts, service identities and credentials, assign an accountable owner to each, grant only the access required, and promptly remove unnecessary access.
Protect accounts and credentials
Require phishing-resistant MFA, use managed and patched devices, monitor for suspicious session activity, and secure API keys using approved secrets-management services. Restrict access to systems that require them and prevent credentials from being exposed in code, documents, logs or prompts.
Separate restricted access and third-party use
Keep restricted-model access and sensitive data separate from routine AI use and experimental environments. Apply security review before exposing applications externally and provide suppliers with limited, auditable access.
Monitor activity and enforce limits
Monitor model access, credential creation, permission changes and unusual usage patterns. Protect audit logs from tampering and configure tested spending, rate and consumption limits that enforce restrictions rather than only generating alerts.
Respond quickly to suspected compromise
Revoke affected API keys, sessions and tokens, isolate compromised devices, preserve logs and investigate unauthorised changes. Remediate the underlying cause before restoring access.
How an organisation's AI access can be compromised
API keys can be exposed in source-code repositories, application configuration files or browser extensions. Vulnerable agent dashboards and other internet-facing applications can also expose credentials used to call model-provider services. An attacker who obtains a working key may then make requests independently of the organisation's legitimate application.
Phishing, information-stealing malware and compromised third-party services provide additional routes to account credentials and authentication tokens. A stolen browser session may allow an attacker to act as an already-authenticated user without completing a fresh multi-factor authentication challenge. Suppliers and contractors can introduce similar risks where they hold organisational credentials or delegated access.
The impact depends on the permissions attached to the compromised identity. Permission to use a model is different from permission to administer an account, create credentials or access stored files. Organisations should assess these privileges separately and avoid assuming that a key used for a simple application has appropriately limited access.
Organisations should also consider the downstream access available through AI agents. A compromised user session, account or agent may be able to interact with connected enterprise systems, invoke tools, access organisational data, or communicate with other agents on the user's behalf. As a result, the practical impact of a compromise may extend beyond the permissions directly assigned to the affected credential.
Recent reports highlight the risks
On 9 September 2026, The Hacker News reported research from Okta that identified still-valid AI API keys and unexpired authentication tokens in data stolen from infected computers.
On 1 September 2026, The Register reported that an attacker spent three weeks consuming public-model credits worth approximately US$600,000. METR's disclosure described an incident in which an authentication flaw in an internet-facing agent dashboard enabled theft of a model-provider API key.
On 21 April 2026, Reuters, citing Bloomberg, reported that unauthorised users had accessed Claude Mythos Preview, which was then restricted to selected organisations. This was reporting about alleged unauthorised access through a vendor environment, rather than confirmation that the model developer’s core infrastructure had been compromised.
Up next
Strategies to mitigate cyber security incidents
The Australian Signals Directorate (ASD) has developed prioritised mitigation strategies to help organisations mitigate cyber security incidents caused by various cyber threats. This guidance addresses targeted cyber intrusions (i.e. those executed by advanced persistent threats such as foreign intelligence services), ransomware and external adversaries with destructive intent, malicious insiders, ‘business email compromise’, and industrial control systems.
Report
Report a cybercrime, incident or vulnerability.