The Droid Wars: Breaking up an AI-orchestrated cyber fraud campaign
Source
factory.ai
Date
Why it matters
If you run or expose an agentic dev platform, this documents a live abuse pattern — attackers automating signups and agent sessions to farm cheap or stolen LLM API access — along with how it was detected and shut down.
Useful as a concrete threat model and detection checklist rather than generic AI-security theory.
A Factory.ai incident report describing how the company detected and shut down an automated attack campaign that tried to hijack its AI software development platform, using it as a node to resell or launder off-label LLM API access at scale.
Transcript
How we detected and disrupted a highly automated cyber operation that attempted to turn our AI software development platform into a node within a worldwide mesh of off‑label LLM usage.