Illegal access to AI models and computing power is rapidly becoming one of the most sought-after commodities in the cybercrime underworld. Hackers are attempting to exploit expensive large language models for extortion, warfare, and espionage.
John Hultquist, chief analyst at Google Threat Intelligence Group, said the cybersecurity unit has observed a significant increase this year in so-called "LLM-jacking" attacks, including the sale of stolen login credentials for public AI tools, as well as groups stealing computing resources in order to run their own models for free. Hultquist, a veteran with 20 years of cybersecurity experience, said: "What we're seeing in the underground market is that an economy is growing around AI access."
Hultquist warned that obtaining expensive AI resources at low cost gives cyberattackers an economic advantage over their targets, since the latter also need to use these AI tools to protect themselves. He said: "Ultimately, all of this gives them some kind of economic or efficiency advantage over us, because they are actually able to obtain these tokens at a much cheaper price."
Researchers at Google's threat intelligence unit found that some marketplaces on the dark web are selling access to AI models from companies such as Anthropic, Google, and OpenAI at discounts of up to 97%. The most advanced AI subscription services for ChatGPT and Claude can cost up to $200 per user per month.
Hultquist said that given that AI labs monitor for signs of such abuse, some sellers even offer "guaranteed access," promising to provide new login credentials for free if the original account is banned. In other cases, criminal groups and state-backed organizations hack into corporate servers hosted in the cloud and deploy their own AI models to run on the target systems. This approach is similar to previous attempts by threat actors to break into third-party computers for cryptocurrency mining.
Hultquist said AI is already being used by "all threat actors," adding that as a result, AI tools must also become an indispensable part of cybersecurity systems in the future. In Anthropic's most recent quarterly report on AI abuse, the company found that threat actors from more than 20 countries, including the United States, the United Kingdom, and Yemen, had attempted to use its Claude tool for malicious activities.
He said: "Anyone who thinks AI is just a fad and wants to let it pass them by will one day wake up and find themselves overwhelmed. They will face more security incidents, more alerts, and more attacks than ever before. We need to get our house in order right now."
Hultquist warned that as more large enterprises seek to deploy customized AI models on their own servers rather than renting computing power from cloud service providers, these systems themselves will also become targets and must therefore be tightly protected. "If you are paying for computing power, and computing power can be very expensive... then this becomes a highly attractive potential resource in the eyes of threat actors."
Hultquist also said that now is the best time for hackers to "sneak into" target accounts and computer servers, because enterprises are still figuring out exactly how much AI resources they will use. He said: "You might think that a sudden sharp increase in computing usage is completely normal, because you have just deployed so much AI infrastructure. This does give some people an opportunity to hide in the noise."