Zeabur Cloud Platform Breach Exposes AI Service API Keys, Causes User Losses

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Taiwan-based AI cloud platform Zeabur suffered a major security breach, exposing users’ environment variables including API keys for AI services like OpenAI and Anthropic. Attackers exploited leaked credentials, leading to unauthorized API usage and financial losses for users. Zeabur’s founder apologized, promised compensation, and is cooperating with authorities.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system-related platform (Zeabur) that manages AI service API keys and environment variables. The unauthorized access and misuse of these credentials led to direct financial harm to users (excessive API usage charges) and potential exposure of sensitive data, fulfilling the criteria for harm to persons or groups (financial harm) and violation of data security. The AI system's malfunction or security failure is a direct cause of the incident. Hence, it meets the definition of an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
IT infrastructure and hosting

Affected stakeholders
ConsumersBusiness

Harm types
Economic/Property

Business function:
ICT management and information security


Articles about this incident or hazard