State Linked Hackers Target AI Development Platforms in New Abuse Campaign

Related

Cybersecurity Leaders to Watch: Louisiana Healthcare

Louisiana’s healthcare sector depends on cybersecurity leaders who can...

Anthropic Unveils Claude Mythos to Find Critical Software Flaws Before Attackers Do

What happened Anthropic unveiled Claude Mythos Preview as the model...

Microsoft Commits $10 Billion to Expand AI and Cybersecurity Infrastructure in Japan

What happened Microsoft announced a $10 billion investment to expand...

Share

What happened

Factory, a San Francisco based AI development platform, reported that it disrupted a campaign run by a state linked threat group. The attackers tried to hijack Factory’s development environment and AI coding tools so they could use them inside a larger global cyber fraud network. The group relied on AI based coding agents to manage infrastructure, move across multiple AI products, and avoid detection.

Who is affected

The direct target was Factory, but the incident affects any organization that uses AI development platforms or AI powered tools. The attackers took advantage of common onboarding paths and free tier access that many AI providers offer. Companies that use AI tools for development, automation, or operations should see this as relevant.

Why CISOs should care

This shows that AI development platforms are now valuable attack surfaces. Threat actors can abuse AI tools to scale criminal operations. It also signals a growing trend where attackers combine AI driven automation with traditional cyber crime. As more organizations adopt AI tools, security teams need to treat these platforms as part of the core attack surface rather than add ons.

3 practical actions

  1. Audit all AI platforms used across the company and identify any that rely on free or trial access.

  2. Tighten onboarding and access controls for AI tools. Use least privilege and monitor all activity.

  3. Add AI platforms to threat models, vendor reviews, and risk assessments to account for provider level compromise or abuse.