Jessica Entwistle
September 2 2026
Attackers stole an API key belonging to METR, an AI safety research organisation, and used it for three weeks to consume approximately $600,000 worth of AI model credits. Infosecurity Magazine reports that the stolen key provided access to large language model APIs from multiple providers. METR has revoked the compromised key and is working with affected vendors to understand how the breach occurred. The incident highlights the operational security challenges organisations face when managing access to high-value cloud AI services, particularly as AI adoption accelerates across business functions.
For UK businesses deploying AI agents, large language models or cloud-based AI services, this incident is a reminder that API keys represent significant financial and operational risk. A single compromised key can result in substantial unexpected costs, potential data exposure if the key is used to query models with sensitive prompts, and reputational damage. The fact that the abuse continued for three weeks suggests that monitoring and alerting for unusual API usage patterns were either absent or insufficient. As AI adoption accelerates, the operational discipline around credential management, usage monitoring and cost controls must keep pace. Organisations that treat AI API keys with the same rigour as production database credentials or payment processing tokens are better positioned to detect and respond to abuse before costs spiral or sensitive data is exposed.
Organisations should review how API keys for AI services are generated, stored, rotated and monitored. Consider implementing usage alerts, spending caps and anomaly detection for AI service consumption to identify unusual patterns before costs escalate. Ensure that access to high-value API credentials is tightly controlled, that keys are rotated regularly, and that unused or legacy keys are revoked. Review whether AI service usage is logged and whether those logs are monitored for suspicious activity such as unusual query volumes, off-hours usage or access from unexpected IP addresses. Consider whether AI governance processes include clear ownership of credential management, cost monitoring and incident response for AI services. This incident is also a prompt to review whether finance teams are alerted to unexpected cloud spending in real time and whether technical teams have visibility into service usage patterns that may indicate compromise.
Source: Infosecurity Magazine