A security nonprofit, METR (Model Evaluation and Threat Research), disclosed two recent cybersecurity incidents involving credential theft and exposure of evaluation data. In March, attackers stole an API key, leading to the consumption of approximately $600,000 in AI model credits. In May, there was a potential exposure of nonpublic evaluation data due to attackers probing METR's infrastructure.
The organization has since increased its security measures, including hiring a security lead and improving logging and monitoring. The incidents highlight vulnerabilities in organizations dealing with AI and the importance of robust security measures.