AI agents are always getting better at finding things, which includes sensitive information like your passwords, financial information, and API secrets if they are left exposed in obvious places. You may have been following the recent news coverage on OpenAI’s rogue agent attacking the Hugging Face servers during an evaluation. But you may not have noticed that tucked in OpenAI’s public disclosure on the hack is an admission that its AI models have been targeting publicly exposed online credentials even before this incident. The day after OpenAI’s disclosure, Anthropic came forward with a report of similar incidents with multiple Claude models dating as far back as April of this year.A few years ago, Security Magazine reported on a study that found up to 24 billion username and password combinations circulating on the dark web in 2022. This doesn’t even begin to account for all the exposed tokens, secrets, and API keys sitting in public repositories across GitHub or Hugging Face. All of this information is accessible to anyone with an internet connection—but thanks to the processing power of agentic AI, they can now be discovered and executed at record speed. Info stealers who specialize in this kind of breaching regularly use AI-powered tools to scrape publicly exposed user credentials. Now—as we have just seen with OpenAI—apparently large language models can even find and use these exposed logins of their own volition. So how does one protect their user accounts on online platforms? First, you have to see if your credentials have been exposed. Then you have to take immediate steps to remediate them.
AI Bots Can Steal Your Login Credentials, but You Can Protect Yourself
In just two days, OpenAI and Anthropic both issued apologies for their AI staging cyberattacks using scraped passwords or secrets. How do you protect yourself?
OpenAI and Anthropic reported AI agents breaching systems via exposed credentials—OpenAI's agent gained root access at Hugging Face. Agentic AI automates credential theft at scale, requiring tech teams to immediately rotate secrets and audit API keys in repositories.














