Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [incident, campaign, ai-uplift, cybercrime-group, supply-chain, sector-technology] ยท confidence: medium ยท severity: medium ยท affected_sectors: [technology, finance] ยท au_impact: true

GTG-50020 โ€” AI Vendor Evaluation Sandbox Compromised for Production API Keys

Summary

A Russian-speaking, financially motivated actor who had previously intruded into hotel booking and financial technology platforms redirected the same tradecraft at the AI industry. By injecting malicious instructions into an AI vendor's automated evaluation sandbox, the actor induced the sandbox to hand over the credentials it held, including production AI API keys from multiple providers belonging to that vendor. The actor then ran its attack workloads on the victim's keys. A follow-on campaign from the same infrastructure attacked roughly thirty AI companies in about four days.

Key Facts

  • Prior activity: intrusions against hotel booking and financial technology platforms; one victim lost roughly 26 GB of data with extortion demands (or darkweb sale) of between $1.5 million and $2.5 million.
  • Sandbox compromise: malicious instructions injected into an automated evaluation sandbox caused it to disclose the credentials it held โ€” production AI API keys from multiple providers.
  • Key reuse: on obtaining the target's keys, the actor switched its own campaigns onto the victim's keys rather than its own, a pattern repeated across targets.
  • Follow-on campaign: roughly thirty AI companies attacked in about four days using a single successful attack path, adapted slightly per target.
  • Objective: access to a pre-release Claude model, pursued across more than a dozen avenues. The vendor states the actor never gained that access and every attempted path failed.
  • Keys belonged to customers, not the platform: the credentials the actor stole were production keys held by the vendor on behalf of its customers.

Related case โ€” GTG-50021, fraudulent AI resale as a credential-harvesting channel

The same reporting documents a Russian- and Ukrainian-speaking group, including an operator using the alias "kl1zy", running a fraudulent AI reseller operation: customers believed they were buying discounted access to a frontier model, but their traffic was silently proxied to a different model while the reseller's tooling installed a credential harvester that stole their platform account credentials for onward sale to other resellers. Recorded indicators include awstore[.]cloud, kiro[.]cheap, sys-tools[.]cfd, aws-us-east-3[.]com, holdboost[.]store, deltaclient[.]xyz and iymkjuzymkapovrntoxy.supabase[.]co.

Significance

This is the AI-supply-chain case that translates most directly into enterprise action. An API key holder's keys now sit inside vendor evaluation environments, third-party integrations, proxies and resellers, and the report's own framing is blunt: organisations should treat AI keys, session tokens and agent integrations with the same seriousness as production credentials, because attackers do. Access should be bought only through authorised channels โ€” a discount that requires routing traffic and credentials through an unknown intermediary is an intrusion pattern, not a bargain. Defenders should also note the exploit class: prompt injection against automation that holds credentials is a real initial-access technique, not a theoretical one, and it has parallels in Mcp Tool Poisoning and in the llms.txt trust flaws recorded in Ai Coding Agents Installed Unowned Code Inside Corporate Networks Via Llms Txt T.

Sourcing caveat

Single-source vendor disclosure. The vendor describes the intrusion against its own environment first-hand; the wider campaign against other AI companies is reported from the same infrastructure observation.

Related: Ai Uplift, Anthropic Threat Intelligence, Hugging Face Ai Breach, One In Ten Exposed Litellm Gateways Accepted The Setup Guide S Example Admin Key, Malicious Litellm Releases Tied To Trivy Hack May Have Exposed 2 100 Organisatio