Impersonation of AI Crawlers Targets Sensitive Cloud Credentials
Article Content
Threat actors are impersonating web crawlers from organizations like OpenAI, Anthropic, and DeepSeek to scan for exposed secrets on internet-facing servers. This activity, reported by GreyNoise on August 28, 2026, involves automated scanners using forged user-agent strings to request sensitive files, including .env configurations and cloud credentials. The attackers are targeting misconfigured servers that may leak API tokens, passwords, and private keys. GreyNoise identified a broader cluster utilizing 13 AI crawler identities from eight companies. The ongoing campaign poses a significant risk to organizations with improperly secured cloud environments. Current status indicates active scanning and credential theft attempts are in progress. Organizations are urged to review their security configurations to mitigate risks.
Key Points: • Threat actors are impersonating AI web crawlers to steal sensitive data. • Automated scanners are targeting misconfigured servers for exposed credentials. • GreyNoise identified 13 AI crawler identities involved in the campaign.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.