⚡
Brief IA
›

LLMjacking: Stolen Credentials and Invoices Over $100,000 a Day

🤖 Models & LLM·Tom Levy·

LLMjacking: Stolen Credentials and Invoices Over $100,000 a Day

LLMjacking: Stolen Credentials and Invoices Over $100,000 a Day
⚡
Key Takeaways
1A black market offers access to corporate AI accounts at heavily discounted prices in 2026
2Costs for businesses can exceed $100,000 per day according to Sysdig
3Access is obtained through phishing, intrusions, leaks, or vulnerabilities, and then resold
4Defense measures include training, audits, least privilege, and rapid key rotation
💡Why it matters — LLMjacking exposes businesses to significant financial losses and requires increased vigilance on AI access security.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

In 2026, a black market offers access to enterprise AI accounts at rock-bottom prices. Estimates suggest daily bills exceeding $100,000 for top-tier models. Security teams are witnessing a significant rise in abuse and are detailing measures to limit exposure.

Discounted Illicit Access and Daily Bills Over $100,000

Sysdig's threat research team estimates that unauthorized use of top-tier AI models can cost around $46,000 and even more than $100,000 per day. Companies may thus face very high billing amounts due to usage by unauthorized individuals. John Hultquist indicates that fraudulent access to models from Anthropic, Google, and OpenAI is being sold at discounts of up to 97%, with some sellers even promising to maintain access if the hacked account is disabled or deleted. According to the analyst, the consequences do not only affect direct victims: some attackers financially exploit AI resources funded by others, while security officials must contend with rising token costs. The Google Threat Intelligence Group has observed a major increase in this phenomenon in 2026, which Hultquist deems potentially costly for businesses. This dynamic thrives on an already active underground economy surrounding access to computing power and AI models, against the backdrop of the criminal popularity of LLMjacking in 2026.

Identified Targets: Computing, Data Theft, and Sabotage

With compromised credentials, malicious actors use AI models without paying for tokens. They perform compute-intensive tasks, divert resources to run their own models or malicious operations, extract sensitive information embedded in victims' models, and can contaminate training datasets, degrading output. Stolen credentials and API keys are then traded on criminal marketplaces. By nature, LLMjacking is the illegal use of AI resources, akin in this domain to the well-known principle of cryptojacking.

How Accounts Fall: Credentials and Keys Recovered Through Multiple Vectors

Attackers seek to obtain credentials or API keys granting access to enterprise AI accounts, often equipped with high or even non-existent usage limits, with token overages billed outside of the subscription. Gaining this access involves intruding into the corporate network, phishing, exploiting data breaches, vulnerabilities, or through insider threats. By analogy, similar to cryptojacking that diverts computing power to mine cryptocurrencies, these techniques target the resources and capabilities associated with AI models.

More Capable Models Require More Power and More Tokens

Organizations like OpenAI and Anthropic are offering increasingly sophisticated, capable, and competent models, which raises the required computing power. This demand translates into the purchase of a greater number of tokens or the choice of higher subscription tiers.

Reducing Exposure: Training, Audits, Least Privilege, and Key Rotation

AI accounts are highly sought after, and their owners must limit the risk of compromise. Phishing constitutes, and should continue to constitute, one of the main sources of credential theft; implementing comprehensive awareness campaigns that go beyond a simple annual session represents a first line of defense. Configuration errors, inappropriate settings, or publicly exposed data facilitate hijacking, making regular checks and frequent updates essential to correct persistent vulnerabilities. Applying the principles of least privilege or zero trust limits employee access only to the resources required and only when necessary. It is recommended to avoid hard-coded credentials and API keys, to rotate all keys and credentials immediately upon suspicion of an incident, and to temporarily revoke access while contacting the provider in case of unusual spikes in activity. Companies are thus called to actively monitor and protect their AI accounts.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.