AI accounts become the new attack surface
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Shoshana Gordon/Axios
Protecting and monitoring companies' internal AI stacks is one of the hottest topics on the floor of this year's Black Hat cybersecurity conference in Las Vegas.
Why it matters: Workers have been experimenting with different AI tools for years now, creating a plethora of new entry points for malicious hackers, experts at this year's show told Axios.
Driving the news: More than 20,000 people are estimated to be at Mandalay Bay Convention Center this week for one of the industry's largest conferences.
- CISOs are looking for ways to safeguard and monitor employees' AI tools, and cyber startups and companies are eager to pitch their solutions.
State of play: Hackers are increasingly buying and reselling ChatGPT, Claude and Gemini credentials they've stolen from legitimate accounts.
- That practice, enabled through popular and pervasive infostealer malware, has been going on since the beginning of ChatGPT's popularity in late 2022, Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told Axios.
- CrowdStrike said in its annual threat hunting report this week that it's observed an 89% surge in attacks using AI to "scale operations, accelerate tradecraft, and directly target AI infrastructure."
- In one campaign, CrowdStrike said, it saw a cybercrime group send nearly 200,000 API requests in just two minutes as part of an "LLMjacking" campaign where they leveraged access to a corporate AI account.
The big picture: At the same time, enterprises are rapidly adopting new, sanctioned AI tools, as well as seeing an influx of unsanctioned, shadow AI deployments on their networks, Bugcrowd CEO Dave Gerry told Axios.
- In one example, Gerry said, his company sent nearly a dozen emails to employees informing them that OpenClaw, an open-source AI agent, was not allowed on corporate networks. Employees kept trying to download it anyway, he said.
Between the lines: Hackers see a variety of benefits from tapping legitimate AI accounts in their attacks.
- Using an employee's AI account can make it harder for IT teams and internal security tools to detect nefarious activity since agents are expected to work at odd hours, Dana Simberkoff, chief risk, privacy and information security officer at AvePoint, told Axios.
- Hackers don't have to spend money on their own tokens, instead handing off the cost to the corporations they're hacking, Meyers added.
- "It's still early days, but I think it's going to become the No. 1 attack vector that we're going to see," Gerry said.
Flashback: Companies saw a similar threat when they moved to the cloud and hackers started hijacking their cloud accounts to get direct access to sensitive corporate files, Meyers added.
The intrigue: A lot of current tools are logging how many tokens an agent is using and other costs for governance and oversight purposes, Simberkoff said.
- But more advanced network monitoring tools are still needed in the market to better detect when agents act out of bounds and what permissions they have.
- "The tools that are available for actually looking at the identity of the agent are still evolving," she said. "That's an opportunity for innovation."
The bottom line: Gerry urged companies to embrace the cyber basics, including educating employees, implementing strong network policies to block shadow AI, and automating network monitoring.
Go deeper: Humans are leaving the door wide open for AI hacking
