Hackers are increasingly stealing access to expensive artificial intelligence accounts and computer servers, creating a growing underground market where powerful AI tools can be obtained cheaply and used for cybercrime, espionage and other malicious activity.
What Is LLM-Jacking?
Security researchers have observed a sharp increase in attacks known as “LLM-jacking”. In these attacks, criminals obtain stolen login credentials for public AI services or break into computing systems so they can use costly AI resources without paying for them.
John Hultquist, chief analyst at Google Threat Intelligence Group, said researchers have seen a major increase in this activity this year. He described a growing underground economy built around access to AI.
How Does LLM-Jacking Work?
LLM-jacking is the unauthorised use of someone else’s AI accounts or computing resources. Attackers may steal login credentials for public AI services or compromise company servers that have access to powerful AI models.
Instead of paying for expensive AI subscriptions and computing power, criminals use the victim’s resources. Stolen access to models from companies including OpenAI, Anthropic and Google is being offered on dark web marketplaces at discounts of up to 97 per cent.
Some underground sellers even offer “guaranteed access”, promising replacement credentials if an account is detected and blocked. Attackers may also break into cloud-hosted servers and install their own AI models, leaving the targeted company to bear the computing cost.
How Much Does Stolen AI Access Cost?
Dark web marketplaces are selling access to AI models from companies including Anthropic, Google and OpenAI at discounts of up to 97 per cent, according to Google Threat Intelligence researchers.
Subscriptions to advanced versions of ChatGPT and Claude can cost as much as $200 per user each month. Stolen access gives attackers the ability to use these tools at a fraction of their normal cost.
Some sellers are even offering “guaranteed access”. If a stolen account is blocked, they promise to provide replacement credentials without charging extra.
Why Are Hackers Targeting Company Servers?
Attackers are not only stealing AI account credentials. Criminal and state-backed groups are also breaking into companies’ cloud-hosted servers and installing their own AI models on the compromised systems.
This allows attackers to use the victim company’s computing power to run AI models without bearing the cost themselves.
The method resembles attacks in which criminals compromise third-party computers to mine cryptocurrency. In one case, a Chinese cyber espionage group allegedly used compromised infrastructure in this way.
How Are Criminals Using AI?
AI tools are already being used by different types of threat actors. Anthropic’s recent quarterly misuse report identified malicious use of its Claude tool by threat actors in more than two dozen countries, including the US, UK and Yemen.
The growing availability of stolen or discounted AI access could give attackers an economic advantage. They can use expensive technology cheaply while organisations must pay for similar tools to defend their systems.
Why Are These Attacks Hard to Detect?
The problem may become harder to detect as more companies run customised AI models on their own servers.
AI systems can require large amounts of computing power. If hackers secretly use those servers, unusually high computing activity could be mistaken for legitimate AI workloads.
Hultquist warned that this creates an opportunity for attackers to hide within the normal increase in computing activity as companies expand their AI infrastructure.
What Should Companies Watch For?
Companies hosting their own AI models will need to treat computing capacity itself as a valuable asset that attackers may try to steal.
As AI use expands, organisations may face attempts to steal account credentials, hijack servers and secretly consume expensive computing resources. Researchers warn that AI security will therefore need to become a larger part of broader cybersecurity planning.
The420 Takeaway
LLM-jacking turns AI access and computing power into something criminals can steal and resell. For companies, protecting AI credentials is no longer enough. They also need to watch who is using their AI systems, monitor unusual computing activity and secure servers running costly AI workloads.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics