METR reports sustained AI-assisted attacks during a separate exposed-query near miss
METR disclosed a sustained external attack campaign using substantial agent automation while a separate read-only SQL query mechanism could access unpublished and some sensitive model data. METR said it found no evidence that the attackers discovered or used that mechanism.
- First observed
- May 1, 2026, 2:00:00 AM
- Disclosed
- Aug 31, 2026, 9:00:00 AM
- Status
- Resolved
- Confidence
- 95%
- Organization
- METR
- Last reviewed
- Sep 4, 2026
Observed
Facts supported by sources
- METR reported a sustained external campaign beginning in early May involving credential stuffing, OAuth-token attempts, service scanning and phishing, with heavy use of agent automation.
- During the same period, an independent researcher found a read-only SQL query mechanism that could reach unpublished and some sensitive model data; METR removed it and said its evidence did not show that the attackers found or used it.
Assessment
Interpretation, not observation
- The exposed query mechanism is a near miss because exploitation and nonpublic data access were not established.
- AI automation appears to have scaled attacker activity, but the campaign remained human-directed.
Impact
Impact
Potential unauthorized access to unpublished evaluation data and sensitive model information, alongside credential and account compromise attempts.
Response
Response
METR temporarily disabled public services, separated public production from internal infrastructure, took the flawed query mechanism offline and commissioned additional red-team testing.