AI agents are always getting better at finding things, which includes sensitive information like your passwords, financial information, and API secrets if they are left exposed in obvious places. You may have been following the recent news coverage on OpenAI’s rogue agent attacking the Hugging Face servers during an evaluation. But you may not have noticed that tucked in OpenAI’s public disclosure on the hack is an admission that its AI models have been targeting publicly exposed online credentials even before this incident. The day after OpenAI’s disclosure, Anthropic came forward with a report of similar incidents with multiple Claude models dating as far back as April of this year.A few years ago, Security Magazine reported on a study that found up to 24 billion username and password combinations circulating on the dark web in 2022. This doesn’t even begin to account for all the exposed tokens, secrets, and API keys sitting in public repositories across GitHub or Hugging Face. All of this information is accessible to anyone with an internet connection—but thanks to the processing power of agentic AI, they can now be discovered and executed at record speed. Info stealers who specialize in this kind of breaching regularly use AI-powered tools to scrape publicly exposed user credentials. Now—as we have just seen with OpenAI—apparently large language models can even find and use these exposed logins of their own volition. So how does one protect their user accounts on online platforms? First, you have to see if your credentials have been exposed. Then you have to take immediate steps to remediate them.