AI Model Evaluator METR Hit by Credential Theft, Probing
Threat actors stole an API key from METR, an AI model evaluator, in a credential theft attack that resulted in unauthorized consumption of $600,000 in public AI model credits. The incident highlights the financial risks associated with compromised API credentials and the targeting of security-focused organizations by threat actors seeking to exploit cloud resources.
The FBI has opened an investigation into a dark web service offering digital scans of over 153 million drivers licenses from US and Canadian residents, apparently sourced from a Louisiana-based identity verification company. Victims whose licenses appear in the catalog have confirmed their documents are being sold through the illicit marketplace, raising serious concerns about the security practices of identity verification platforms. The breach represents one of the largest driver's license data exposures and has triggered federal law enforcement involvement.
Nutex Health, a Houston-based healthcare facilities operator, disclosed a data breach occurring in August in which cybercriminals stole patient and employee information. The attackers subsequently attempted extortion using the compromised data, prompting the company to file a report with federal regulators.
Aesto Health, a U.S. healthcare technology company, disclosed a breach exposing personal and health information of more than 9.5 million individuals after attackers gained unauthorized access to its AWS infrastructure. The company discovered the incident on December 18, 2025. The breach resulted in exposure of sensitive healthcare and personal data across a significant portion of the affected population.