All Incidents
A Million AI Systems Are Wide Open Right Now. Your Conversations Are Inside.
MAY 5, 2026SECURITY FAILURE

A Million AI Systems Are Wide Open Right Now. Your Conversations Are Inside.

Security firm Intruder scanned the public internet and found approximately 1,000,000 AI systems wide open — no password, no authentication, no lock. Their conclusion: AI infrastructure is "more vulnerable, exposed, and misconfigured than any software we've ever investigated."

What's inside those open systems? Everything people typed into them. Health questions. Financial data. Private conversations. The kind of things you type at 2 a.m. thinking nobody is watching.

1,652 servers had zero authentication. 518 of them were holding live API keys to OpenAI, Anthropic, Google, and DeepSeek — meaning anyone who found them could use those credentials to run queries, access data, and rack up bills, all billed to the company that left the door open.

This is not a breach. No attacker had to do anything clever. The door was just open.

The companies that deployed these systems sold their customers "AI-powered" products. Nobody told those customers that the backend was sitting on the open internet with no lock on it. Nobody was watching. Nobody audited the configuration. The users never knew.

They sold the dream. We flag the wreckage.

HOFFICIALHITL Score
HITL Score12/100
Why this matters to youNo jargon — just what it means

A security firm went looking across the open internet and found roughly a million AI systems sitting wide open — no password, no lock, nothing. They called it more exposed and misconfigured than any software they'd ever examined. These are supposed to be secured products. Instead, the back doors were simply hanging open for anyone to walk through.

And what's inside? Everything people typed in — health worries, money questions, private 2 a.m. confessions you'd never say out loud. On top of that, hundreds of these open servers held live master keys to the big AI companies, meaning a stranger could run up huge bills on someone else's account.

So how does it touch you? You don't have to be careless to get burned here. You can use one of these 'AI-powered' apps exactly as told, and the company on the other end may have left your private words sitting on the open internet with no lock — and never mentioned it. The door wasn't picked. It was just left open, with your secrets behind it.

🖤 Explained by Babycakes.
Read the full source →
Source: INTRUDER / THE HACKER NEWS