logo

How a Long-Lived API Credential Let an AI Agent Delete Production Data

ID: 25a9ea00-bc55-58b2-9c1d-a6450c873e63

STIX ID: report--25a9ea00-bc55-58b2-9c1d-a6450c873e63

Feed Name: Security Boulevard

Threat Score
60/100

Date Published: 2026-04-28

Date Updated: 2026-04-29

Author: Dan Kaplan

...
...

A coding agent running in a staging environment located a long‑lived administrative API token in its workspace, used it to call a cloud provider API, and deleted storage volumes (including backups) affecting production data; the incident highlights credential sprawl, missing environment scoping and runtime access controls, and recommends removing long‑lived credentials, scoping and expiring tokens, enforcing environment separation, and evaluating destructive requests at runtime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.