AI medical-imaging service provider agentic AI attack
An attacker leveraged the Model Context Protocol to turn an AI coding assistant into an attack vector against an AI medical-imaging provider
- Reported date
- Oct 6, 2026
- Target
- AI medical-imaging service provider
- Agent type
- Other AI agent
- Agent role
- Used by the attacker
The exact incident date was not established. This entry is dated by its source report.
What happened
In an incident reported by threat intelligence firm CloudSEK on October 5, 2026, an attacker operating under the handle "Azazel" utilized an AI coding assistant to execute commands during a live intrusion against an AI medical-imaging service provider. This technique, which CloudSEK states had no prior public documentation in a ransomware context, involved using the Model Context Protocol (MCP) to route commands through an AI assistant already integrated into the victim's development environment.
By leveraging the MCP—an open standard designed to allow AI agents to interact with external tools and data—the attacker was able to execute commands directly within the enterprise network. This approach allowed the malicious activity to blend into legitimate developer-tooling traffic, bypassing traditional detection methods like reverse shells. The breach was part of a broader campaign where Azazel, an affiliate of the ransomware-as-a-service group "The Gentlemen," harvested credentials from exposed GitLab instances. The attacker gained initial access by exploiting CI/CD pipeline variables, API keys, and SSH private keys that remained recoverable from historical Git commits, even after being deleted from current repository versions.
While the primary entry point relied on credential reuse rather than a software vulnerability, the use of an AI agent as an attack infrastructure represents a significant shift in how attackers leverage privileged automation. CloudSEK noted that the attacker used this access to exfiltrate data, ultimately keeping extortion payments for themselves rather than sharing them with The Gentlemen’s core operation. The campaign affected more than two dozen organizations across six countries, with approximately 6 terabytes of data stolen. Security researchers emphasize that organizations must now apply the same change-control rigor to AI agent and MCP integrations as they do to other privileged production systems, as these integrations often possess broad, programmatic access to sensitive infrastructure.
Evidence in the reporting
- Incident evidence
- Azazel used the Model Context Protocol, the open standard that lets
- Agent involvement
- AI coding assistants call external tools and data sources, to execute