Stolen AI Credentials Fuel a Booming Black Market in LLMjacking
Stolen AI accounts are a hot commodity: access to Anthropic, Google, and OpenAI models sells at up to 97% off, and hijacked enterprise usage can exceed $100,000 per day.

Updated
Why it matters
- Sysdig's Threat Research Team estimates unauthorized AI account use costs victims around $46,000 per day, and over $100,000 on top-tier models.
- Google Threat Intelligence Group's John Hultquist reported a 'major increase' in LLMjacking over 2026, with illicit access to Anthropic, Google, and OpenAI models sold at up to 97% off.
- Some underground traders guarantee ongoing access to compromised AI accounts even if the account is revoked or closed.
Sysdig's Threat Research Team estimates that unauthorized use of enterprise AI accounts can cost victims roughly $46,000 per day, and over $100,000 per day on top-tier models. That figure frames the stakes behind what Google Threat Intelligence Group calls a "major increase" in LLMjacking over 2026 — the illegal use of AI resources and credentials that belong to someone else.
John Hultquist, chief analyst for Google Threat Intelligence Group, told the Financial Times that his unit has tracked the trend as it spreads across the underground economy. Criminals are not just stealing compute anymore. They are stealing access to the models themselves.
The AI equivalent of cryptojacking
The name invites the comparison, and it holds. Cryptojacking is the theft of computing power to mine cryptocurrency illicitly. LLMjacking is the AI equivalent: using AI power and resources that don't belong to you.
In practice, this means criminals hunt for credentials or API keys that grant authorized access to business AI accounts. These accounts often carry high usage limits — or none at all — with token overspill charged outside of typical subscription costs. That billing structure is exactly what makes a stolen account so valuable, and so expensive for the victim.
Criminals obtain username and password combinations or API keys through several routes, according to the reporting: access to a corporate network, phishing, data breaches, vulnerabilities, and insider threats. Once inside, they can use the model without paying for a single token themselves.
The uses vary. Attackers can perform high-level computing tasks that require large volumes of tokens. They can harness the stolen computing resources to run their own malicious AI models or tasks. They can extract and steal sensitive corporate information that victims have fed into their models. They can poison training datasets, ruining output. And once stolen, credentials and API keys can be resold on the underground to other cybercriminal groups — which multiplies the original breach.
Why the costs keep climbing
The economics cut in the attackers' favor. As models offered by organizations including OpenAI and Anthropic advance in sophistication, capacity, and skill, they require more computing power. More power means more tokens to purchase, or a higher-tier subscription. For an enterprise whose account has been hijacked, inflated billing from unauthorized users can climb rapidly.
The black market has adjusted to demand. Hultquist's team has spotted illicit access to AI models offered by Anthropic, Google, and OpenAI selling for up to 97% off legitimate prices. Some traders even guarantee ongoing access should a compromised account be revoked or closed — a warranty model that mirrors legitimate software-as-a-service sales.
The damage is not confined to direct billing losses. Hultquist points out that by leveraging stolen AI power, cybercriminals gain an "economic advantage" in conducting attacks, using AI resources paid for by others, while defenders are constrained by rising token costs. In other words, the same price curve that pressures legitimate security budgets subsidizes the attackers.
Why it matters
The story matters because enterprise AI spend has become an attack surface with a direct dollar figure attached. Every API key, every enterprise subscription, and every high-limit account is now an asset that criminals can monetize — either by consuming tokens themselves or by reselling access at a steep discount. For companies budgeting millions for AI adoption in 2026, LLMjacking turns that investment into a liability unless the underlying credentials are defended as aggressively as financial accounts.
How businesses can defend themselves
The recommendations from the reporting are concrete and mostly familiar to security teams — which does not make them less neglected.
Treat phishing training as ongoing, not annual. Phishing remains one of the main causes of account theft and exploitation. The guidance calls for training and awareness programs that go beyond an annual tick-box exercise.
Audit configurations and patch relentlessly. Misconfigured instances, settings, and exposed data can all lead to LLMjacking. Security teams need the time and capacity to run frequent audits and maintain regular patch cycles to close unpatched vulnerabilities that could provide unauthorized network access.
Adopt least privilege and zero trust. Under this framework, employees access only the resources they need for their work, and only when they need them. That reduces the risk of admin-level accounts being exploited for malicious purposes.
Eliminate hardcoded credentials and API keys. Hardcoded secrets are a standing invitation. Organizations that believe a breach has occurred should rotate all credentials and keys without delay.
Watch usage and act fast. If unusual AI usage appears — spikes in activity, for example — the recommendation is to consider temporarily revoking access and contacting the provider immediately.
What comes next
Hultquist's assessment suggests the underground market will keep growing as long as model access remains both valuable and poorly guarded. The 97% discount and the access guarantees indicate a mature, competitive supply chain. Businesses that treat AI credentials like any other privileged secret — rotated, audited, and scoped to least privilege — will deny that market its inventory. Those that don't will keep funding it, one stolen token at a time.
Original: ft.com
More from Elena Vasquez
Show full bio
Market editor covering media and advertising at AI In Context.
144 articles
Related articles
- Microsoft Disrupts EvilTokens, AI Chatbot Platform Behind 12,000 Account Hacks
- OpenAI Bans Accounts Linked to DPRK Threat Actors Using AI for Intrusion Research
- OpenAI Bans Korean-Language Accounts Tied to Malware Development
- AI Models Keep Cheating on Tests, and Researchers Are Quitting
- Nvidia launches AI agent security platform and $150bn buyback