Anthropic, OpenAI and Perplexity: Threat actors are posing as AI crawlers to hunt for exposed credentials

Anthropic, OpenAI and Perplexity: Threat actors are posing as AI crawlers to hunt for exposed credentials

AI Crawler Spoofing Used to Scan for Exposed Credentials, Researchers Warn

Cybersecurity firm GreyNoise has uncovered a campaign where attackers disguise malicious scanning activity as traffic from legitimate AI crawlers operated by OpenAI, Anthropic, Google, Perplexity, and others. By forging user agent strings headers that identify the requesting client threat actors evade detection while probing websites for exposed credentials and configuration files.

Researchers explained that while AI companies publish their crawler names and IP ranges to help site owners verify legitimate traffic, attackers exploit this system by spoofing these identifiers. Between July 28 and August 23, 2026, GreyNoise observed six AI crawler names from four companies appearing under a single HTTP client fingerprint, which had previously used over 1,500 different user agent strings most mimicking ordinary browsers.

The malicious traffic originated from 824 IP addresses across 795 separate /24 networks, none of which matched the published ranges of the spoofed AI companies. Unlike legitimate crawlers, which frequently request /robots.txt (a file outlining crawling rules), the forged traffic ignored this path entirely. In contrast, GreyNoise found that Anthropic’s real crawler requested /robots.txt in 12% of its traffic during the same period.

The scanners targeted sensitive files, including .env (environment configuration), .env.production, .env.bak, cloud access keys, private keys, and /.aws/credentials. While GreyNoise could not confirm whether any files were successfully exfiltrated or which organizations were affected, it published the 824 malicious IP addresses and targeted paths for site owners to cross-check against their logs.

The findings highlight the challenges of distinguishing legitimate AI crawler traffic from malicious activity, particularly when attackers leverage undocumented user agents such as forged Amazon crawler names to further obscure their scans.

Source: https://www.helpnetsecurity.com/2026/08/31/ai-crawlers-scan-exposed-credentials/

OpenAI cybersecurity rating report: https://www.rankiteo.com/company/openai

Perplexity cybersecurity rating report: https://www.rankiteo.com/company/perplexity-ai

Anthropic cybersecurity rating report: https://www.rankiteo.com/company/anthropic

"id": "OPEPERANT1788188170",
"linkid": "openai, perplexity-ai, anthropic",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'attack_vector': 'Spoofed AI crawler user agents',
 'data_breach': {'file_types_exposed': ['.env',
                                        '.env.production',
                                        '.env.bak',
                                        '/.aws/credentials'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Environment configuration files',
                                              'Cloud access keys',
                                              'Private keys',
                                              'AWS credentials']},
 'date_detected': '2026-07-28',
 'date_publicly_disclosed': '2026-08-23',
 'description': 'Cybersecurity firm GreyNoise uncovered a campaign where '
                'attackers disguised malicious scanning activity as traffic '
                'from legitimate AI crawlers operated by OpenAI, Anthropic, '
                'Google, Perplexity, and others. By forging user agent '
                'strings, threat actors evaded detection while probing '
                'websites for exposed credentials and configuration files. The '
                'malicious traffic targeted sensitive files, including *.env*, '
                '*.env.production*, *.env.bak*, cloud access keys, private '
                'keys, and */.aws/credentials*.',
 'impact': {'data_compromised': 'Potential exposure of environment '
                                'configuration files, cloud access keys, '
                                'private keys, and AWS credentials',
            'identity_theft_risk': 'High (if credentials were exfiltrated)'},
 'investigation_status': 'Ongoing (no confirmation of successful exfiltration)',
 'lessons_learned': 'Attackers can exploit AI crawler identifiers to evade '
                    'detection, highlighting the need for stricter '
                    'verification of crawler traffic beyond user agent strings '
                    'and IP ranges.',
 'motivation': 'Credential harvesting, data exfiltration',
 'post_incident_analysis': {'root_causes': 'Lack of robust verification for AI '
                                           'crawler traffic, allowing spoofing '
                                           'of user agent strings and IP '
                                           'ranges.'},
 'recommendations': ['Implement additional verification mechanisms for AI '
                     'crawler traffic (e.g., challenge-response tests).',
                     'Monitor for unusual scanning patterns, such as requests '
                     'ignoring */robots.txt*.',
                     'Cross-check logs against published lists of malicious '
                     'IPs and targeted paths.',
                     'Restrict access to sensitive configuration files and '
                     'credentials.'],
 'references': [{'date_accessed': '2026-08-23', 'source': 'GreyNoise'}],
 'response': {'communication_strategy': 'Public disclosure of malicious IPs '
                                        'and targeted paths',
              'third_party_assistance': 'GreyNoise (research and disclosure)'},
 'title': 'AI Crawler Spoofing Used to Scan for Exposed Credentials',
 'type': 'Scanning/Probing',
 'vulnerability_exploited': 'Lack of verification for AI crawler traffic'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.