Threat Intelligence

AI Safety Researcher METR Targeted in Credential Theft, Racks Up $600,000 in Stolen AI Credits

Dark Reading · 2 Sept 2026
Key Takeaway Treat API keys and cloud credentials like sensitive passwords—store them securely, rotate them often, and set billing alerts to catch unusual usage early.

METR, a nonprofit known for evaluating the safety and capabilities of AI models, has been targeted by threat actors who stole an API key belonging to the organisation. The attackers used the compromised credential to run up $600,000 in charges against public AI model services, highlighting how valuable API keys have become as a target for cybercriminals.

This incident is a reminder that credential theft isn't limited to traditional IT systems—API keys tied to cloud and AI services can be just as lucrative for attackers, and just as damaging if left unmonitored. Once stolen, such keys can be used to rack up massive costs or enable further malicious activity, often before the victim organisation even notices anything is wrong.

For small and medium businesses increasingly relying on AI tools and cloud-based services, this case underscores the importance of treating API keys with the same care as passwords: storing them securely, rotating them regularly, and setting usage alerts or spending caps wherever possible.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.