Security researchers are warning of a booming underground market for stolen artificial intelligence account credentials, creating a lucrative new revenue stream for cybercriminals. This trend, known as LLMjacking, involves the unauthorized use of corporate AI resources and is becoming a significant financial risk for enterprises in 2026.
John Hultquist, chief analyst at Google’s Threat Intelligence Group, told the Financial Times that his unit has observed a “major increase” in LLMjacking activities throughout the year. The practice is analogous to cryptojacking; rather than stealing computing power to mine cryptocurrency, hackers steal access to AI models and large language model (LLM) services to perform high-level computing tasks at little to no cost to themselves.
The scheme typically begins with the theft of usernames, passwords, or API keys. Cybercriminals acquire these credentials through corporate network intrusions, phishing attacks, data breaches, or insider threats. Once obtained, these keys provide access to enterprise AI accounts, which often feature high usage limits or token overspill charges that exceed standard subscription costs.
The financial impact on victims can be severe. As AI models from providers like OpenAI and Anthropic grow more sophisticated, they require greater computing power and, consequently, more tokens. Sysdig’s Threat Research Team estimates that unauthorized usage on top-tier models can inflate bills by approximately $46,000 per day, with costs potentially exceeding $100,000 daily.
Hultquist noted that illicit access to models from major providers such as Anthropic, Google, and OpenAI is available online at discounts of up to 97%. Some vendors even guarantee ongoing access, promising replacement accounts if a compromised one is revoked. This gives attackers an economic advantage, allowing them to leverage stolen AI power for malicious purposes while defenders struggle with rising operational costs.
Experts recommend several strategies for businesses to mitigate these risks. First, organizations should implement robust phishing awareness and training programs that go beyond annual compliance exercises. Second, security teams should conduct frequent audits and regular patch cycles to address misconfigured settings and unpatched vulnerabilities.
Adopting a zero-trust or least-privilege framework is also critical, ensuring employees only access the resources necessary for their roles. Finally, businesses should avoid hardcoding credentials and immediately rotate all keys if a breach is suspected. If unusual spikes in AI usage are detected, organizations should consider temporarily revoking access and contacting their service provider.
I’d love to see the invoice when my AI writes the code to mine crypto. At least it’s efficient.
Do regular users really have access to these high-cost enterprise tiers, or is it just misconfigured admins?
Stop hardcoding API keys, people! This is literally basic hygiene. Why is this still happening?
Forty-six thousand dollars a day? I need to know if I can bill my boss for my own curiosity.
Wait, so my company pays for the electricity while hackers profit? That’s a new low.