ThreatCluster

Impersonation of AI Crawlers Targets Sensitive Cloud Credentials

First seen 1 Sep 2026, 21:30 UTC GbhackersCybersecuritynews 65

Article Content

Browse articles
ThreatCluster

Threat actors are impersonating web crawlers from organizations like OpenAI, Anthropic, and DeepSeek to scan for exposed secrets on internet-facing servers. This activity, reported by GreyNoise on August 28, 2026, involves automated scanners using forged user-agent strings to request sensitive files, including .env configurations and cloud credentials. The attackers are targeting misconfigured servers that may leak API tokens, passwords, and private keys. GreyNoise identified a broader cluster utilizing 13 AI crawler identities from eight companies. The ongoing campaign poses a significant risk to organizations with improperly secured cloud environments. Current status indicates active scanning and credential theft attempts are in progress. Organizations are urged to review their security configurations to mitigate risks.

Key Points: • Threat actors are impersonating AI web crawlers to steal sensitive data. • Automated scanners are targeting misconfigured servers for exposed credentials. • GreyNoise identified 13 AI crawler identities involved in the campaign.

Timeline

2026-08-28
GreyNoise reports impersonation campaign
GreyNoise published findings on threat actors impersonating AI crawlers to scan for sensitive files on exposed servers.
Gbhackers
2026-09-01
Reporting by multiple outlets
Both Gbhackers and Cybersecuritynews published articles detailing the impersonation campaign and its impact.
Cybersecuritynews