Hackers Go after Major LLM Services by Cracking Misconfigured Proxy Servers



  • GreyNoise recorded 91,000 attack sessions against exposed AI systems between October 2025 and January 2026.
  • The campaigns included tricking servers into “calling home” and conducting mass polls to map AI models.
  • Malicious actors attacked misconfigured proxy servers and tested OpenAI, Gemini, and other LLM APIs at scale.

Experts have warned that hackers are targeting misconfigured proxy servers to see if they can get into the underlying Large Language Model (LLM) service.

GreyNoise researchers recently installed a fake and exposed AI system to see who would try to interact with it.



Leave a Comment

Your email address will not be published. Required fields are marked *