AI Incidents
Back to incident register
Source reviewedSecurity breachMedium

METR reports sustained AI-assisted attacks during a separate exposed-query near miss

METR disclosed a sustained external attack campaign using substantial agent automation while a separate read-only SQL query mechanism could access unpublished and some sensitive model data. METR said it found no evidence that the attackers discovered or used that mechanism.

First observed
May 1, 2026, 2:00:00 AM
Disclosed
Aug 31, 2026, 9:00:00 AM
Status
Resolved
Confidence
95%
Organization
METR
Last reviewed
Sep 4, 2026

Observed

Facts supported by sources

  • METR reported a sustained external campaign beginning in early May involving credential stuffing, OAuth-token attempts, service scanning and phishing, with heavy use of agent automation.
  • During the same period, an independent researcher found a read-only SQL query mechanism that could reach unpublished and some sensitive model data; METR removed it and said its evidence did not show that the attackers found or used it.

Assessment

Interpretation, not observation

  • The exposed query mechanism is a near miss because exploitation and nonpublic data access were not established.
  • AI automation appears to have scaled attacker activity, but the campaign remained human-directed.

Impact

Impact

Potential unauthorized access to unpublished evaluation data and sensitive model information, alongside credential and account compromise attempts.

Response

Response

METR temporarily disabled public services, separated public production from internal infrastructure, took the flawed query mechanism offline and commissioned additional red-team testing.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.