Skip to content

DATA PROTECTION

AI-Driven Credential Theft: What It Means for Backup and Recovery Strategy

July 30, 2026
Robert CallaghanSenior Product Marketing Manager

In July 2026, OpenAI disclosed that one of its own AI models had hacked another company. According to NPR, an autonomous agent running on a combination of models was operating in a sandbox environment when it found a way onto the open internet in pursuit of its assigned task. It picked a target on its own: Hugging Face, a well-known repository for AI training and testing data. The agent found a vulnerability, broke in, and used that access to obtain the credentials it needed to move deeper into Hugging Face's servers.

Colin Shea-Blymyer, a cybersecurity research fellow at Georgetown's Center for Security and Emerging Technology, told NPR it represented the highest level of autonomy yet documented in the use of a large language model for cyber operations. This was reconnaissance, targeting, credential theft, and exploitation, chosen and executed end-to-end by the AI itself.

It’s the clearest evidence yet of something security teams have been warning about for a while: the hard part of an attack, the part that used to require a skilled person, is now something a model can do on its own. Credential theft, the oldest trick in the book, no longer needs a con artist or an open door. It just needs a task.

Not an isolated incident

A Harvard Kennedy School research team led by Fred Heiding ran a controlled, human-subjects study comparing fully AI-automated phishing emails against ones written by human experts. The AI-generated emails achieved a 54% click-through rate, statistically identical to the human-written ones, and roughly four and a half times the rate of generic phishing. The researchers' automated tool pulled accurate, usable information about each target from public sources in 88% of cases, using little more than a LinkedIn profile, a few company posts, or a conference bio.

Put the two examples together and the pattern is hard to miss. One case shows a model choosing a target and stealing credentials with no human directing each step. The other shows that even an AI-written lure performs as well as a skilled human, at a fraction of the cost and time. Different techniques, same conclusion: the skill and patience that used to limit the rate at which these attacks could happen isn't a limiting factor anymore.

Where the damage actually happens

If the usual playbook for stealing credentials has changed, companies can’t rely on the same barriers they’ve typically relied on: training people to spot a bad email, or hoping a compromised password gets caught before it's used. Because in nearly every version of this attack, the credential was never the finish line. It was just step one.

Most ransomware and data-destruction attacks don't start at the storage layer. They start with exactly what happened to Hugging Face: a stolen credential, a way in that didn't need to be sophisticated to work. But they tend to end at storage, because that's where the recovery copy lives. Once an attacker, human or otherwise, has the right credentials, the rest of the playbook is almost straightforward: find the backups, delete the recovery points, encrypt production, and in some cases, delete the storage account entirely. At that point, paying the ransom becomes the only option left on the table.

Building a backup strategy that assumes compromise

Backup storage can't be treated as a passive destination anymore, someplace data goes to sit until it's needed. It has to function as an active part of the defense, built specifically for the moment when everything upstream of it has already failed.

Wasabi addresses this with a set of controls built for exactly this scenario. Object Lock and immutable retention keep backup data from being altered or deleted for as long as the retention period holds, even by someone with valid administrator credentials. Compliance Mode protects recovery points even if an admin account itself is compromised, closing off the exact move an attacker makes once they're inside. Multi-User Authorization removes single-administrator control from protected, destructive actions. Customers can designate up to three independent security contacts, and each assigned contact must approve requests, such as deleting a storage account or bucket, before Wasabi will proceed. Layer MFA, least-privilege IAM policies, encryption, audit logging, and egress alerts on top, and an attacker must overcome multiple independent controls across identity, access, data, and exfiltration.

For the copies that genuinely cannot be lost, there's one more layer. Wasabi Covert Copy™ keeps a hidden, logically isolated version of your data somewhere ransomware, a compromised admin account, or plain human error can't reach. It’s a version of the backup that isn't part of the attack surface at all, because it was never visible to begin with.

These controls are more than just compliance checkboxes. Together, they're the practical version of a shift already underway across security thinking.

The assume breach mindset

Security teams have a name for this shift: assume breach. It's the working premise behind zero trust architecture: stop designing defenses around the hope that an attacker never gets in, and start designing them around the certainty that eventually, one will.

Applied to backup, assume breach means the recovery copy has to survive the same compromise that took down everything else. Not a separate password. Not a different login on the same identity system. A layer with its own rules, immune to the credentials that just failed everywhere else, because those credentials will fail. Object Lock, Compliance Mode, Multi-User Authorization, and  Covert Copy™ exist for that one job: making sure the attacker who gets past every other control still hits a wall at the one copy that matters.

Hardening backup this way doesn't prevent the breach. It means the business can still recover its own data, on its own terms, instead of the attacker's.

Defense-in-depth, built for real attacks

See how Wasabi's defense-in-depth security keeps your recovery data safe even after every other control fails.

Explore Wasabi Security

Yes. Password policies and MFA reduce risk but don't eliminate it — MFA fatigue attacks, session token theft, and AI-generated social engineering can all bypass these controls without ever "breaking" a password. That's why backup protection needs to assume a credential will eventually be compromised, rather than relying solely on prevention at the identity layer.

Recovery time depends on data volume and infrastructure, but the key difference is that a protected, immutable copy is recoverable at all. Without it, recovery often means negotiating with attackers or rebuilding from partial, degraded backups, both of which take significantly longer than restoring from an untouched copy.

It applies broadly. Smaller companies are frequently targeted precisely because they're assumed to have weaker controls, and a ransomware event can be more existential for a smaller business with less financial cushion to absorb downtime or ransom demands.

No. They're a last line of defense, not a substitute for reducing the chance of compromise in the first place. Endpoint security, MFA, and employee training still matter, they're just no longer sufficient on their own, since this piece argues prevention will eventually fail regardless of how strong those layers are.

A standard backup can typically be altered, encrypted, or deleted by anyone with the right administrative access, which is exactly what attackers target once they're inside. An immutable backup is locked against changes or deletion for a set period, regardless of who's holding valid credentials at the time.

Related article

data protection
DATA PROTECTIONWhen a cyber attack stops the production line: Lessons from the Fairlife ransomware incident

Most Recent

Why every neocloud needs a cloud storage strategy

AI workloads move constantly, and every move costs money. Here's why neoclouds need a storage strategy as deliberate as their compute plan.

GLM-5.2 just changed the ransomware conversation: When AI levels up the attacker

An open-weight AI model called GLM-5.2 is making ransomware attacks faster. Learn why defense in depth is critical to keeping backups recoverable.

Wasabi MCP Beta is live: Your AI agents now have direct access to cloud storage

Wasabi MCP is now in beta. Connect any AI agent to your Wasabi cloud storage with 140+ tools, no custom code, no egress fees, and no API charges. Start building today.

SUBSCRIBE

Storage Insights from the Storage Experts

Storage insights sent direct to your inbox.

Subscribe