2 Sources
[1]
Google warns of surge in AI account theft and LLM-jacking attacks
Google security researchers have warned of a sharp rise in "LLM-jacking" attacks this year, as cybercriminals steal access to AI models and computing infrastructure. John Hultquist, chief analyst at Google's Threat Intelligence Group, told the Financial Times that dark web marketplaces are selling
[2]
AI Access Becomes New Commodity for Cybercriminals | PYMNTS.com
That's according to a report Sunday (Sept. 27) by the Financial Times (FT), which said this trend is happening as hackers look to employ expensive large language models (LLMs) for extortion, warfare and espionage. John Hultquist, chief analyst for Google Threat Intelligence Group, told the FT the
Share
Copy Link
Google's Threat Intelligence Group reports a sharp rise in LLM-jacking attacks, with cybercriminals selling stolen credentials to AI models from OpenAI, Anthropic and Google on dark web marketplaces at up to 97% discounts. Attackers are also breaching enterprise cloud servers to deploy their own AI models, shifting computing costs onto victims.

Google's Threat Intelligence Group has identified a significant surge in LLM-jacking attacks throughout this year, marking a troubling evolution in AI security threats
1
. John Hultquist, chief analyst at Google Threat Intelligence Group, revealed that cybercriminals are actively stealing computing resources and selling unauthorized access to AI models from major providers including OpenAI, Anthropic and Google2
. Dark web marketplaces now offer these stolen credentials at discounts reaching up to 97%, creating a burgeoning underground economy centered on AI access1
.Premium subscriptions to services such as ChatGPT and Claude can cost as much as $200 per user per month, making stolen credentials an attractive commodity for criminal buyers
1
. Hackers selling pilfered login credentials have established sophisticated operations, with some vendors offering "guaranteed access" services that promise replacement credentials at no charge if original accounts are suspended1
. This economic model gives attackers a distinct advantage, as Hultquist explained: "They can acquire that computing power at a much lower cost, while we have to pay full price to defend ourselves"1
.Beyond AI account theft, cybercriminals have escalated tactics by breaching enterprise cloud servers to deploy their own AI models on compromised systems
1
. This approach mirrors earlier cryptojacking operations where hackers hijacked machines to mine cryptocurrency, but now shifts heavy computing costs onto victims for AI workloads1
. Google researchers have observed these methods being used by both criminal groups and an active Chinese cyber espionage group that has previously targeted the United States1
. Companies in early stages of enterprise AI deployment face particular risk, as they may misinterpret attacker-driven spikes in computing use as normal demand from newly installed systems1
.Related Stories
Anthropicreported in its latest quarterly misuse report that malicious attempts to exploit Claude tools have been detected in more than two dozen countries
1
. Hultquist emphasized the universal adoption of AI by threat actors, stating that "every threat actor is using AI" for purposes including extortion, warfare and espionage1
2
. Recent research from PYMNTS Intelligence shows 42% of companies now use three or more AI defense tools as part of layered cybersecurity frameworks, while 50% identify AI-generated vendor impersonation emails as their top threat2
.Hultquist issued a stark warning about the urgency of adapting cybersecurity frameworks to address AI-enabled threats. "Anybody who decides that AI is a fad and wants to let it just wash over them is going to wake up one day underwater," he told the Financial Times. "They're going to have more incidents, more alerts, more attacks than they've ever seen before. We have to get our house in order now"
2
. The financial advantage that stealing computing resources provides to attackers means organizations must invest in AI-powered defense systems to match the sophistication of threats. Close to 90% of finance leaders already consider verifying vendors a moderate or major burden, highlighting the resource strain that AI-enabled fraud places on companies2
.Summarized by
Navi
02 Sept 2026•Technology

03 Nov 2025•Technology

12 Feb 2026•Technology
