Security firm Huntback recently uncovered a massive data breach targeting Spanish small and mid-sized businesses, driven by an operator who relied heavily on AI to assemble their toolkit. By leaving a single server directory open to the internet, the attacker exposed 10,428 files, including shell history, a custom exfiltration script, and 15 GB of stolen data. The operation, dubbed 'Operation Open Ledger,' demonstrates how modern threat actors are leveraging AI agents like 'opencode' to automate reconnaissance and exploit development, turning commodity tools into a targeted extraction pipeline.
The Cloud API Heist
The core of the theft didn't require installing malware on the victim's network. Instead, the crew used 'gitleaks' to scan exposed Git repositories, recovering Azure Entra ID application credentials. With these service-principal secrets, they minted OAuth tokens and accessed the Microsoft Dynamics 365 Business Central REST API directly. This allowed them to bulk-dump entire tenants, including customers, general ledgers, and invoices, appearing as legitimate integration traffic. The operator maintained versioned backups of their custom scripts, such as 'bc_full_dump.py' (v2.0.2), indicating a structured, albeit automated, engineering effort.
An AI-Assisted Exploit Kit
Parallel to the cloud theft, the operator deployed a six-product exploit kit for internet-facing appliances, including SonicWall SMA1000, JetBrains TeamCity, and BeyondTrust. The quality of these modules varied significantly, revealing their origins. One README for a SmarterMail exploit explicitly credited 'ChatGPT' for its creation. The kit also included a full Active Directory arsenal, featuring mimikatz, BloodHound, and Cobalt Strike, alongside a Sliver C2 and an xmrig Monero miner. This mix of Chinese, Russian, and English language artifacts in the code confirms the toolkit was assembled from public sources via AI, rather than authored by a single developer.
Victim Impact and Data Sensitivity
The breach impacted ten distinct Spanish SMBs, with a notable skew toward dental and healthcare practices. The exfiltrated data went beyond basic financial records, including thousands of payment-card numbers, IBANs, and sensitive health records, all of which trigger GDPR reporting requirements in Spain and the EU. One single victim's general ledger export reached 3.9 GB, representing a complete map of their financial operations. The largest single victim accounted for 6.6 GB of data, highlighting the scale of the compromise for these small entities.
Key Takeaways
- Secret Hygiene is Critical: The initial entry point was a leaked Azure app secret in a Git repo; regular scanning with tools like gitleaks is non-negotiable.
- AI Lowers the Barrier to Entry: Operators are using AI agents to assemble and customize exploit kits, making sophisticated attacks accessible to mid-tier threat actors.
- Monitor API Abuse: Unusual bulk reads from the Business Central REST API using client-credentials grants should be flagged, even if the traffic looks legitimate.
- Patch Internet-Facing Appliances: The crew exploited known CVEs in SonicWall, TeamCity, and KEMP LoadMaster; keeping these devices updated is essential to block the intrusion path.
The Bottom Line
This incident proves that 'AI-assisted' doesn't mean 'AI-authored,' but it does mean faster, cheaper, and more scalable attacks. Small businesses must treat cloud API credentials with the same rigor as on-prem passwords, because a single leaked secret can now trigger a full-scale exfiltration event.
Mitigation Strategies
Defenders should immediately rotate any Azure app secrets and prefer workload-identity federation over long-lived keys. For the Business Central API, implement conditional access policies and alert on bulk OData reads from unfamiliar IPs. Additionally, disable LLMNR/NBT-NS to prevent relay attacks and enforce SMB signing to break the Active Directory pivot chain that the operator used to move laterally once inside.