GreyNoise finds forged ClaudeBot and GPTBot traffic hunting for credentials
GreyNoise reported on August 28 that scanners forging AI-crawler names probed the open web for credential files from 824 addresses across 795 separate networks between July 28 and August 23, 2026, with activity peaking on August 23. Six forged crawler names arrived in matched volume, tracing to Anthropic, OpenAI, Google and Perplexity, alongside separately forged Amazon crawler names.
One name exposes the forgery outright: 263,849 sessions carried the “Google-Extended” string, even though Google’s own documentation states that token has no separate HTTP request user agent at all — meaning none of those sessions could have been genuine. The traffic requested paths including /.env, /app/.env, /api/.env, /.aws/credentials, and /.git/config. GreyNoise’s report does not say whether any file was actually returned or name any organization affected.
GreyNoise’s recommendation is to verify crawler identity against companies’ published IP ranges rather than trust the user-agent string — the same gap this wire flagged on August 27, when none of the three major AI-crawler operators could be shown to meet all four of Cloudflare’s new access conditions.
Why it matters: It shows the AI-crawler user-agent string, the thing most access rules are keyed on, is trivially forgeable at scale — the exact identity gap Cloudflare's new crawler-verification conditions are meant to close.
The record: AnthropicOpenAIGoogle
Via GreyNoise ↗ · PPC Land ↗
Posted to the wire August 30, 2026.