AI credential theft and supply chain attacks are becoming a datacentre problem
https://etimg.etb2bimg.com/thumb/msid-133234216,imgsize-123104,width-1200,height=627,overlay-etciso,resizemode-75/cybercrime-fraud/ai-credential-theft-and-supply-chain-attacks-are-becoming-a-datacentre-problem.jpg

Datacentre operators are facing a new kind of exposure as cyber criminals move beyond conventional ransomware and into the machinery that powers artificial intelligence. Stolen AI access tokens, compromised software packages and downstream credential leaks are now being monetised through underground markets, creating a direct threat to compute capacity, cloud spend and operational resilience.
Recent findings from ETDatacenters, drawing on reports from CloudSEK, Palo Alto Networks’ Unit 42 and Kaspersky, show how quickly the risk surface has widened. The common thread across the research is simple: as AI workloads become more central to enterprise operations, the credentials, keys and software dependencies that support them are becoming more valuable to attackers.
Why AI access tokens are attracting criminals
Unit 42, the threat intelligence arm of Palo Alto Networks, has identified a tactic it describes as token jacking. Under this model, attackers steal legitimate AI access credentials, then route the stolen compute through gray-market resellers that convert access into cash. According to ETDatacenters, this is not just credential theft in the traditional sense. It is an attempt to turn AI infrastructure itself into a commodity that can be consumed, diverted or resold.
Cdr Raj Shastrakar, who heads Unit 42 in India and SAARC, said the method reflects a broader shift in attacker behaviour. Instead of only stealing passwords or tokens for direct misuse, criminals are increasingly harvesting long-lived keys such as application programming interface credentials tied to AI platforms. Once these are in hand, they can be used to burn through expensive compute allocations or passed on through intermediary brokers known as transfer stations.
The economics help explain the appeal. Many organisations grant developers broad permissions in order to speed up experimentation and application building. That can mean high spending limits, the ability to create new keys and access to model provisioning tools. If such an account is compromised, losses can escalate quickly before the breach is spotted. ETDatacenters reported that companies have faced million-dollar bills when stolen credentials are used at scale before the abuse is contained.
How gray-market compute reselling works
The resale layer is what makes token jacking especially difficult to police. Once access is stolen, the attacker does not always need to use the capacity directly. Instead, the compute can be pushed through proxy networks and sold at a discount to buyers who want cheap access to AI resources. That creates a shadow market around legitimate infrastructure and makes attribution harder for defenders.
This also complicates incident response for datacentre and cloud teams. A stolen key may still appear to be valid, and the activity may look like normal usage until the bill spikes or the pattern of requests becomes suspicious. The longer the access remains active, the more time attackers have to extract value from the environment.
For operators, the issue is no longer limited to endpoint security or perimeter defence. It now extends to identity governance, API key hygiene, usage monitoring and the controls surrounding model access. In AI-heavy environments, the token itself can be as sensitive as the workload it unlocks.
Supply chain attacks are widening the blast radius
CloudSEK has separately flagged a large-scale supply chain incident attributed to the threat actor group TeamPCP, which began in March 2026 and is still active, according to ETDatacenters. The campaign reportedly exposed infrastructure keys across thousands of downstream projects, including cloud credentials, repository tokens, SSH keys, Kubernetes secrets, package-publishing credentials, environment variables and AI provider keys.
The significance of such an incident lies in its reach. When a package or dependency is compromised, the harm does not stop at the first victim. Downstream users may inherit the same poisoned code or copied secrets, allowing attackers to move laterally across projects and organisations. CloudSEK warned that stolen credentials can stay usable for weeks or even months unless they are rotated promptly and the resulting activity is investigated thoroughly.
That makes software supply chain security a datacentre issue as much as a developer issue. Modern infrastructure depends on a dense web of open-source libraries, automation tools and deployment pipelines. If any of those layers are compromised, the attacker may gain a route into compute environments that were never directly targeted in the first place.
Open-source dependence is adding pressure
Kaspersky’s latest research reinforces how broad the problem has become. The security firm found that supply chain attacks are now among the most common cyber threats worldwide, with nearly one in three organisations reporting such an incident over the past year. Sergey Lozhkin, head of APAC and META research units at Kaspersky GReAT, said malicious packages targeting open-source software rose 37 per cent in 2025 to 19,484 detections, up from 14,197 in 2024. Hacktool detections also increased 11 per cent year-on-year, according to the same research.
Those numbers matter because open-source components are now embedded in most enterprise applications and AI infrastructure stacks. The more heavily organisations depend on third-party code, the greater the need for continuous verification of what is being installed, updated and deployed. The challenge is not just identifying a malicious package once it appears, but also tracing where it has been used and what secrets it may have exposed along the way.
What this means for datacentre operators and enterprises
The combined message from the reports is that AI has created a fresh layer of cyber risk sitting directly on top of compute and storage infrastructure. For datacentre operators, this means stronger controls around privileged access, tighter monitoring of unusual usage patterns and closer scrutiny of the software supply chain that feeds workloads into the environment.
Enterprises building AI applications will also need to treat access tokens and API keys as high-value assets, not convenience tools. That includes limiting permissions, shortening credential lifetimes, rotating secrets quickly and checking whether downstream systems have inherited compromised dependencies.
For India’s datacentre and cloud ecosystem, the warning is especially relevant. As AI adoption accelerates across banking, manufacturing, technology and public sector workloads, the attack surface will expand in step. The risk is not only of data theft, but of infrastructure being quietly consumed, resold or contaminated through trusted software paths.
The security lesson is clear: in the AI era, attackers are targeting the plumbing as much as the payload. Companies that want resilience will need to secure tokens, packages and pipelines with the same urgency once reserved for firewalls and malware defence.
Firewall Support Company in India All type of Firewalls Support Provider Company in India












