Hackers attack top LLM services by hijacking misconfigured proxies


  • GreyNoise recorded 91,000 attack sessions against exposed AI systems between October 2025 and January 2026.
  • Campaigns included encouraging servers to “call home” and mass surveys to map AI models.
  • Malicious actors targeted misconfigured proxies and tested OpenAI, Gemini, and other LLM APIs at scale.

Hackers are targeting misconfigured proxies to see if they can penetrate the underlying Large Language Model (LLM) service, experts have warned.

GreyNoise researchers recently set up a fake AI system on display to see who would attempt to interact with it.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top