LLM Hijacking: A Rising Cyber Threat You Need to Know About

www.news4hackers.com-llm-hijacking-a-rising-cyber-threat-you-need-to-know-about-llm-hijacking-a-rising-cyber-threat-you-need-to-know-about

LLM-Jacking is a growing cyber threat where hackers steal access to expensive AI accounts and servers, creating an underground market for malicious use.

What Is LLM-Jacking?

Security experts have identified a surge in attacks termed “LLM-jacking,” where adversaries acquire unauthorized access to public AI services or infiltrate computing systems to exploit costly AI resources without payment. John Hultquist, chief analyst at Google Threat Intelligence Group, noted a significant rise in such activities this year, highlighting the emergence of a clandestine economy centered on AI access.

“John Hultquist, chief analyst at Google Threat Intelligence Group, noted a significant rise in such activities this year, highlighting the emergence of a clandestine economy centered on AI access.”

How Does LLM-Jacking Work?

Unauthorized Utilization of AI Resources

This tactic involves the unauthorized utilization of AI accounts or computational infrastructure. Attackers may obtain login credentials for public AI platforms or breach company servers with access to high-value AI models. By leveraging these resources, cybercriminals avoid paying for subscriptions or cloud computing costs.

Dark Web Marketplaces

Stolen access to models from firms like OpenAI, Anthropic, and Google is being sold on dark web marketplaces at discounts of up to 97%. Some vendors even provide “guaranteed access,” offering replacement credentials if an account is flagged and suspended.

Deployment of Malicious AI Models

Additionally, threat actors may infiltrate cloud-hosted servers to deploy their own AI models, shifting the financial burden to the compromised organization.

How Much Does Stolen AI Access Cost?

According to Google Threat Intelligence researchers, dark web platforms are offering access to AI models from major providers at steep discounts. Monthly subscriptions for premium versions of ChatGPT and Claude can reach $200 per user, while stolen credentials enable attackers to use these tools at a fraction of the standard price. Certain sellers guarantee uninterrupted access, promising to supply new credentials at no additional cost if an account is detected and blocked.

Why Are Hackers Targeting Company Servers?

Beyond stealing AI account credentials, malicious actors and state-sponsored groups are infiltrating corporate cloud infrastructure to install their own AI models. This allows them to harness the victim’s computational power without incurring costs. The approach mirrors earlier tactics where attackers compromised third-party systems for cryptocurrency mining. A Chinese cyber espionage group is suspected of employing similar methods through compromised networks.

How Are Criminals Using AI?

AI tools are already being exploited by various threat actors. Anthropic’s latest misuse report revealed that its Claude model was used maliciously by threat groups across over 25 countries, including the United States, United Kingdom, and Yemen. The proliferation of stolen or discounted AI access could provide attackers with a financial edge, enabling them to deploy advanced technology at reduced costs while organizations face higher expenses to defend against such threats.

Why Are These Attacks Hard to Detect?

The challenge of identifying LLM-jacking incidents is compounded by the increasing deployment of customized AI models on corporate servers. AI systems often require substantial computational resources, and unauthorized usage could be mistaken for legitimate workloads. Hultquist warned that as companies expand their AI infrastructure, attackers may exploit the normal rise in computing activity to mask their presence.

What Should Companies Watch For?

Organizations hosting AI models must treat computing capacity as a critical asset vulnerable to theft. As AI adoption grows, enterprises may face attempts to steal credentials, hijack servers, or covertly consume expensive resources. Experts emphasize that AI security must become a central component of broader cybersecurity strategies. LLM-jacking transforms AI access and computational power into tradable assets for cybercriminals. For businesses, safeguarding AI credentials is no longer sufficient. They must also monitor who is utilizing their systems, detect anomalous computing patterns, and secure servers running high-cost AI workloads.



About Author

en_USEnglish