LLMjacking: Stolen Credentials and Invoices Over $100,000 a Day

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
In 2026, a black market offers access to enterprise AI accounts at rock-bottom prices. Estimates suggest daily bills exceeding $100,000 for top-tier models. Security teams are witnessing a significant rise in abuse and are detailing measures to limit exposure.
Discounted Illicit Access and Daily Bills Over $100,000
Sysdig's threat research team estimates that unauthorized use of top-tier AI models can cost around $46,000 and even more than $100,000 per day. Companies may thus face very high billing amounts due to usage by unauthorized individuals. John Hultquist indicates that fraudulent access to models from Anthropic, Google, and OpenAI is being sold at discounts of up to 97%, with some sellers even promising to maintain access if the hacked account is disabled or deleted. According to the analyst, the consequences do not only affect direct victims: some attackers financially exploit AI resources funded by others, while security officials must contend with rising token costs. The Google Threat Intelligence Group has observed a major increase in this phenomenon in 2026, which Hultquist deems potentially costly for businesses. This dynamic thrives on an already active underground economy surrounding access to computing power and AI models, against the backdrop of the criminal popularity of LLMjacking in 2026.
Identified Targets: Computing, Data Theft, and Sabotage
With compromised credentials, malicious actors use AI models without paying for tokens. They perform compute-intensive tasks, divert resources to run their own models or malicious operations, extract sensitive information embedded in victims' models, and can contaminate training datasets, degrading output. Stolen credentials and API keys are then traded on criminal marketplaces. By nature, LLMjacking is the illegal use of AI resources, akin in this domain to the well-known principle of cryptojacking.
How Accounts Fall: Credentials and Keys Recovered Through Multiple Vectors
Attackers seek to obtain credentials or API keys granting access to enterprise AI accounts, often equipped with high or even non-existent usage limits, with token overages billed outside of the subscription. Gaining this access involves intruding into the corporate network, phishing, exploiting data breaches, vulnerabilities, or through insider threats. By analogy, similar to cryptojacking that diverts computing power to mine cryptocurrencies, these techniques target the resources and capabilities associated with AI models.
More Capable Models Require More Power and More Tokens
Organizations like OpenAI and Anthropic are offering increasingly sophisticated, capable, and competent models, which raises the required computing power. This demand translates into the purchase of a greater number of tokens or the choice of higher subscription tiers.
Reducing Exposure: Training, Audits, Least Privilege, and Key Rotation
AI accounts are highly sought after, and their owners must limit the risk of compromise. Phishing constitutes, and should continue to constitute, one of the main sources of credential theft; implementing comprehensive awareness campaigns that go beyond a simple annual session represents a first line of defense. Configuration errors, inappropriate settings, or publicly exposed data facilitate hijacking, making regular checks and frequent updates essential to correct persistent vulnerabilities. Applying the principles of least privilege or zero trust limits employee access only to the resources required and only when necessary. It is recommended to avoid hard-coded credentials and API keys, to rotate all keys and credentials immediately upon suspicion of an incident, and to temporarily revoke access while contacting the provider in case of unusual spikes in activity. Companies are thus called to actively monitor and protect their AI accounts.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.