Stolen access to premium artificial intelligence accounts is becoming a growing underground commodity, with cybercriminals increasingly targeting Claude, Gemini and AI coding tools such as Cursor Pro and Devin.
New findings from Google Threat Intelligence Group show that both buyers and sellers of compromised AI accounts increased across underground forums in 2026. Average marketplace prices for these accounts also more than doubled compared with the previous year.
The trend builds on the wider rise of “LLM-jacking”, where attackers steal credentials or compromise cloud environments so they can use expensive AI models and computing resources without paying for them.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Claude and Gemini accounts draw strongest underground demand
Google said demand is concentrated heavily on Claude and Gemini credentials, while autonomous coding tools such as Cursor Pro and Devin are also becoming increasingly attractive to cybercriminals.
The reason is simple: powerful AI services are expensive.
Premium subscriptions, API access and high-performance AI compute can become a significant cost for criminals trying to automate phishing, malware development, credential theft or other operations.
Stealing an existing account allows them to bypass part of that expense.
Some underground buyers are also looking for coding-assistant credentials because these services can provide access to powerful models designed to write, analyse and modify software.
That makes them useful not only for legitimate developers, but also for attackers looking to automate technical work.
Underground prices for AI accounts more than doubled in 2026
Google’s monitoring of criminal forums found that average prices for compromised AI accounts more than doubled during 2026.
That is an important signal.
A rising underground price usually indicates that criminals believe the stolen access has real economic value.
Earlier illicit AI markets were often dominated by so-called “jailbroken” chatbots or services claiming to remove safety restrictions.
The market is now shifting towards genuine access to mainstream commercial models.
Instead of relying on a weaker criminal-only chatbot, an attacker can buy access to Claude, Gemini or a coding assistant that has already been paid for by someone else.
Infostealer malware is targeting AI credentials directly
Google says widely distributed credential-stealing malware remains one of the main ways these accounts are obtained.
Researchers examined commands issued through several prominent infostealers, including LUMMAC.V2, STEALC.V2, VIDAR and ACRSTEALER, and found evidence that attackers are specifically hunting for AI-related configuration data.
That represents an evolution from simply stealing browser passwords.
In May, ACRSTEALER operators pushed rules designed to collect configuration files used by AI coding assistants.
Google said those targets included Cline’s secrets.json file and Continue AI’s config.yaml file.
Such files can contain plaintext API keys or custom model-routing details.
If stolen, they may give attackers direct access to paid AI quotas or to the victim’s own model infrastructure.
30,000 exposed files fed one credential-stealing campaign
Separate research from Check Point shows how large this problem can become.
Its AI Security 2026 report describes a campaign called Bissa Scanner that harvested credentials for Anthropic, OpenAI, Google and other AI providers from more than 30,000 exposed configuration files. AI credentials were reportedly the most common type of secret taken from those files.
Those stolen credentials can then feed underground resale markets.
Criminal buyers may use them to gain model access at a lower price, conceal their activity behind a legitimate customer account or avoid having their own identity directly connected to the AI service.
That makes stolen AI access useful both financially and operationally.
LLM-jacking increasingly targets entire cloud environments
The problem is not limited to individual accounts.
Google says threat actors are also compromising enterprise cloud environments specifically to hijack computing resources for AI workloads. It describes this activity as LLM-jacking.
In this scenario, attackers may gain access to a company’s cloud account and use its GPUs, model endpoints or paid AI APIs.
The victim may not immediately lose data.
Instead, the company may discover the attack through unexpectedly high model usage or a sudden increase in its cloud bill.
The technique resembles cryptojacking, where attackers secretly used someone else’s computing power to mine cryptocurrency.
The difference is that the stolen resource is now AI compute.
AI accounts are becoming assets worth stealing
The change reflects how valuable access to leading models has become.
Google says the cost of premium model access and high-performance computing remains one of the major barriers preventing threat actors from using AI more extensively.
Stolen accounts solve that problem.
The attacker gets a powerful model while someone else pays.
That means AI credentials are beginning to resemble other valuable underground commodities such as stolen credit cards, remote-desktop logins or compromised cloud accounts.
The value can be even greater when the stolen credential provides API access rather than only a consumer chatbot subscription.
An API key can allow automated requests at large scale and may connect directly to a company’s paid quota.
Criminals are also stealing AI developer configurations
The targeting of developer tools creates another risk for companies.
AI coding assistants increasingly sit inside software-development workflows and may have access to repositories, cloud infrastructure or internal tools.
A stolen configuration file can therefore expose more than the AI account itself.
It may reveal API keys, endpoints or credentials that allow an attacker to move deeper into an organisation.
That makes AI developer environments increasingly attractive targets for credential-stealing malware.
Companies that protect ordinary passwords but leave AI configuration files unencrypted can therefore still be exposed.
Detection may begin with a bill rather than an alert
LLM-jacking can remain hidden for longer than some conventional attacks.
The legitimate account still works.
Employees may not notice anything unusual.
There may be no ransomware note or visible system disruption.
Instead, the first warning could be a spike in token consumption, an unfamiliar login, abnormal API calls or unexpectedly high cloud charges.
That means AI usage itself has to become part of normal security monitoring.
Businesses should track which accounts can access expensive models, where those requests originate and whether model consumption suddenly deviates from normal patterns.
AI security now includes protecting the account itself
The latest findings show that AI security is no longer only about preventing prompt injection, harmful outputs or model theft.
The account and infrastructure around the model are now valuable targets in their own right.
Companies using AI services need to protect API keys, developer configuration files and cloud credentials with the same seriousness as other production secrets.
Multi-factor authentication, restricted permissions and rapid key rotation can reduce risk.
Monitoring usage and billing patterns can also help identify abuse before costs grow.
The more AI becomes integrated into business systems, the more its credentials will resemble any other high-value digital asset.
What this means for you: If you use paid AI accounts or coding assistants, protect API keys and configuration files like banking or cloud credentials. Unexpected usage spikes, unfamiliar logins or sudden increases in AI bills can be early signs that someone else is using your access.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics