Threat actors are posing as AI crawlers to hunt for exposed credentials

Threat actors are posing as AI crawlers to hunt for exposed credentials
Attackers are forging AI crawler identities from OpenAI, Anthropic, Google, Perplexity, and Amazon to hide automated scans that search websites for exposed credentials and configuration files. GreyNoise found the activity came from 824 IP addresses targeting paths like /.env and /.aws/credentials, but did not confirm whether any secrets were actually stolen. #OpenAI #Anthropic #Google #Perplexity #Amazon #ClaudeBot

Keypoints

  • Attackers are spoofing AI crawler user agents to disguise scanning traffic.
  • The fake traffic targeted exposed credentials and sensitive configuration files.
  • GreyNoise linked six crawler names to the same 824 IP addresses.
  • None of the suspicious addresses matched published vendor IP ranges.
  • Targets included /.env, /.env.production, /.env.bak, and /.aws/credentials.

Read More: https://www.helpnetsecurity.com/2026/08/31/ai-crawlers-scan-exposed-credentials/