LLM Enumeration Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 8, 2026
Last Seen
January 8, 2026

The LLM Enumeration Campaign is a threat campaign where adversaries systematically probe and enumerate Large Language Models (LLMs) and their deployment environments (APIs and chatbots) to identify weaknesses, misconfigurations, and data leakage paths.

Overview

The LLM Enumeration Campaign is a threat campaign where adversaries systematically probe and enumerate Large Language Models (LLMs) and their deployment environments (APIs and chatbots) to identify weaknesses, misconfigurations, and data leakage paths. Key traits include automated probing of prompts, attempts to bypass safeguards via prompt-injection techniques, and data extraction attempts from model outputs. The campaign highlights the growing risk surface as organizations increasingly rely on LLM-based services for critical operations.

Related Threat Clusters

  • Hackers Exploit Misconfigured Proxies to Access LLM Services

    Threat actors have been targeting misconfigured proxy servers to gain unauthorized access to commercial large language model (LLM) services. This campaign, which began in late December 2025, has seen over 91,000 attack…

    4 articles · Updated January 9, 2026

Recent Intelligence Reports

  • Threat Actors Actively Targeting LLMs — Greynoise · January 8, 2026

CVSS v3.1 Breakdown