Skip to content

Security1 publisher2 min readPublished

Australian Signals Directorate tells AI customers to guard their own keys and sessions

Australia's Signals Directorate says attackers are using stolen AI API keys, tokens and hijacked sessions to get into organisations' AI services. Its guidance tells customers to protect those credentials themselves. In one reported case, a stolen key ran up about US$600,000 in model credits over three weeks.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Australian Signals Directorate tells AI customers to guard their own keys and sessions
Generated illustration

What happened

  • ASD says intruders with that access can generate harmful material, consume the organisation's AI credits and disrupt legitimate work.
  • Okta research, reported by The Hacker News on September 9, found still-valid AI API keys and unexpired authentication tokens in data stolen from infected computers.
  • METR disclosed that an authentication flaw in an internet-facing agent dashboard let an attacker steal the model-provider API key behind the credit bill.
  • Reuters, citing Bloomberg, reported on April 21 alleged unauthorised access to the restricted Claude Mythos Preview through a vendor environment; the reporting did not confirm a breach of the developer's core infrastructure.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost The owner of a leaked key pays for whatever an attacker consumes, and the bill grows every day the theft goes unnoticed.
  • constraint Phishing-resistant MFA does not stop a stolen session, so stealer infections on staff machines have to be caught through device management and session monitoring.
  • exposure An AI agent with tool access carries a compromised identity into connected enterprise systems and data, so the agent's permissions set how far one theft reaches.
  • decision Model-use rights and account-admin rights are granted separately, so each AI credential needs its own named owner and its own permission review.

All three reported cases trace back to credentials or environments held by customers and their vendors [10][12][13]. Most of ASD's entry points are storage mistakes: API keys left in source-code repositories, configuration files and browser extensions, and internet-facing agent dashboards that expose the keys used to reach model providers [4]. Phishing, information-stealing malware and compromised third-party services are also on the list [18].

A stolen key needs no exploit. Whoever holds it can send requests straight to the AI service without going through the organisation's own application [5]. The METR bill of about US$600,000 over three weeks works out to roughly US$28,600 a day [1]. ASD wants security teams to watch model access, credential creation, permission changes and unusual consumption, and to protect the audit logs [16].

ASD's wording is that organisations should not rely solely on the security measures AI developers provide [3]. The controls it names are ones the customer runs: phishing-resistant MFA, managed and patched devices, monitoring for suspicious session activity, approved secrets-management services for API keys, and keeping credentials out of code, documents, logs and prompts [15].

Of all the routes, third-party access has the least public evidence behind it. Suppliers and contractors add exposure when they hold organisational credentials or delegated access [7]. ASD wants that access limited and auditable. It also wants restricted-model access and sensitive data kept apart from routine and experimental AI use [17]. The vendor-route example, access to Claude Mythos Preview, is still an allegation, reported by Reuters citing Bloomberg [13].

The report does not tie the activity to a named group. The three cases were reported on April 21, September 1 and September 9, and each describes a different route [13][11][10]. On this evidence the activity is the same kind of credential abuse turning up at different organisations, not a single campaign by one actor.

What to watch

  • Any attribution of the stolen-key activity to a named group would turn a credential-hygiene warning into a campaign story.
  • A statement from the model developer on whether the Claude Mythos Preview access reached anything beyond the vendor environment.
  • Further Okta findings on how long AI API keys and tokens stay valid after they appear in stealer logs.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories