ZDNET’s key takeaways
- Safety consultants warn of a rising market in stolen AI account credentials.
- LLMjacking, the unlawful use of AI assets, is a well-liked legal pattern in 2026.
- Companies should monitor and shield their accounts. Right here’s how.
Safety consultants warn that it’s not simply synthetic intelligence (AI) going rogue that we now have to fret about — there’s additionally a booming underground financial system for promoting entry to your AI fashions and computing energy.
Talking to the Monetary Instances, John Hultquist, chief analyst for Google Menace Intelligence Group, mentioned that the cybersecurity unit has seen a “main improve” in what is named LLMjacking over 2026, a pattern that might value companies dearly.
What’s LLMjacking?
If cryptojacking got here to thoughts, you’re heading in the right direction. Whereas cryptojacking describes stealing computing energy to illicitly mine cryptocurrency, LLMjacking is the AI equal: utilizing AI energy and assets that don’t belong to you.
Additionally: OpenAI’s Dots: Like OpenClaw declawed – for $200/mo ChatGPT Professional customers
Within the cybercriminal world, this implies making an attempt to safe credentials or API keys that give a legal licensed entry to enterprise AI accounts, which frequently have excessive utilization limits, or doubtlessly none in any respect — with token overspill charged exterior of typical subscription prices.
Cybercriminals can get hold of username and password combos or API keys by getting access to a company community, stealing them through phishing, information breaches, vulnerabilities, or insider threats. This grants cybercriminals the chance to make use of an AI mannequin with out paying for the tokens themselves, for causes akin to:
- Performing high-level computing duties requiring tokens
- Harnessing computing assets to run their very own malicious AI fashions or duties
- Extracting and stealing delicate company info fed right into a sufferer’s mannequin
- Poisoning coaching datasets, ruining output
As soon as stolen, credentials and API keys can be bought on the underground to different cybercriminal teams.
The rising value of LLMjacking
As AI fashions provided by organizations, together with OpenAI and Anthropic, proceed to advance in sophistication, capability, and ability, they require extra computing energy.
The extra energy you want, the extra tokens you could buy — or the upper the extent of subscription you need to buy.
For enterprise corporations, inflated billing attributable to unauthorized customers can climb quickly, with Sysdig’s Menace Analysis Crew estimating prices of round $46,000 and even over $100,000 per day on top-tier fashions.
‘Assured’ entry to dirt-cheap AI fashions
Mix the uncooked energy of AI and uncovered credentials that may be simply bought on-line, and you may see why LLMjacking is exploding in reputation.
Additionally: Who’s accountable for catching rogue AI brokers? You might be
In keeping with Hultquist, the safety crew has noticed illicit entry to AI fashions provided by corporations together with Anthropic, Google, and OpenAI for as much as 97% off, and a few merchants even assure ongoing entry ought to a compromised account be revoked or closed.
The monetary injury isn’t restricted to the victims of LLMjacking. Because the analyst factors out, by leveraging stolen AI energy, cybercriminals now achieve an “financial benefit” in conducting assaults by utilizing AI assets paid for by others, whereas defenders are constrained by rising token prices.
How companies can defend themselves
AI accounts are a scorching commodity, and it’s as much as house owners to scale back the chance of compromise — particularly with such excessive monetary penalties at stake.
Phishing is, and possibly all the time might be, one of many essential causes of account theft or exploitation, so implementing worthwhile coaching and consciousness packages past an annual tick-box train is likely one of the first methods companies can shield themselves.
Additionally: Why phishing coaching doesn’t cease your workers from clicking rip-off hyperlinks
Misconfigured situations, settings, and uncovered information can all result in LLMjacking, and so safety groups needs to be given the time and capability to run frequent audits — in addition to common patch cycles to repair unpatched vulnerabilities that might present unauthorized community entry.
One other crucial solution to defend your group towards LLMjacking is to undertake the rules of least privilege. Least privilege, or zero belief, is a framework wherein workers have entry solely to the assets they want for his or her work, and solely after they want them, which may cut back the chance of admin-level accounts being exploited for malicious functions.
Lastly, keep away from hardcoded credentials and API keys, and companies that imagine there was a safety breach ought to rotate all credentials and keys at once. If uncommon AI utilization, akin to spikes in exercise, is discovered, then contemplate briefly revoking entry and speak to your supplier.


