ZDNET’s key takeaways
- Security experts warn of a growing market in stolen AI account credentials.
- LLMjacking, the illegal use of AI resources, is a popular criminal trend in 2026.
- Businesses must monitor and protect their accounts. Here’s how.
Security experts warn that it’s not just artificial intelligence (AI) going rogue that we have to worry about — there’s also a booming underground economy for selling access to your AI models and computing power.
Speaking to the Financial Times, John Hultquist, chief analyst for Google Threat Intelligence Group, said that the cybersecurity unit has seen a “major increase” in what is known as LLMjacking over 2026, a trend that could cost businesses dearly.
What is LLMjacking?
If cryptojacking came to mind, you’re on the right track. While cryptojacking describes stealing computing power to illicitly mine cryptocurrency, LLMjacking is the AI equivalent: using AI power and resources that don’t belong to you.
Also: OpenAI’s Dots: Like OpenClaw declawed – for $200/mo ChatGPT Pro users
In the cybercriminal world, this means trying to secure credentials or API keys that give a criminal authorized access to business AI accounts, which often have high usage limits, or potentially none at all — with token overspill charged outside of typical subscription costs.
Cybercriminals can obtain username and password combinations or API keys by gaining access to a corporate network, stealing them via phishing, data breaches, vulnerabilities, or insider threats. This grants cybercriminals the opportunity to use an AI model without paying for the tokens themselves, for reasons such as:
- Performing high-level computing tasks requiring tokens
- Harnessing computing resources to run their own malicious AI models or tasks
- Extracting and stealing sensitive corporate information fed into a victim’s model
- Poisoning training datasets, ruining output
Once stolen, credentials and API keys can also be sold on the underground to other cybercriminal groups.
The rising cost of LLMjacking
As AI models offered by organizations, including OpenAI and Anthropic, continue to advance in sophistication, capacity, and skill, they require more computing power.
The more power you need, the more tokens you need to purchase — or the higher the level of subscription you must purchase.
For enterprise companies, inflated billing caused by unauthorized users can climb rapidly, with Sysdig’s Threat Research Team estimating costs of around $46,000 and even over $100,000 per day on top-tier models.
‘Guaranteed’ access to dirt-cheap AI models
Combine the raw power of AI and exposed credentials that can be easily purchased online, and you can see why LLMjacking is exploding in popularity.
Also: Who’s responsible for catching rogue AI agents? You are
According to Hultquist, the security team has spotted illicit access to AI models offered by companies including Anthropic, Google, and OpenAI for up to 97% off, and some traders even guarantee ongoing access should a compromised account be revoked or closed.
The financial damage isn’t limited to the victims of LLMjacking. As the analyst points out, by leveraging stolen AI power, cybercriminals now gain an “economic advantage” in conducting attacks by using AI resources paid for by others, while defenders are constrained by rising token costs.
How businesses can defend themselves
AI accounts are a hot commodity, and it is up to owners to reduce the risk of compromise — especially with such high financial consequences at stake.
Phishing is, and probably always will be, one of the main causes of account theft or exploitation, so implementing valuable training and awareness programs beyond an annual tick-box exercise is one of the first ways businesses can protect themselves.
Also: Why phishing training doesn’t stop your employees from clicking scam links
Misconfigured instances, settings, and exposed data can all lead to LLMjacking, and so security teams should be given the time and capacity to run frequent audits — as well as regular patch cycles to fix unpatched vulnerabilities that could provide unauthorized network access.
Another critical way to defend your organization against LLMjacking is to adopt the principles of least privilege. Least privilege, or zero trust, is a framework in which employees have access only to the resources they need for their work, and only when they need them, which can reduce the risk of admin-level accounts being exploited for malicious purposes.
Finally, avoid hardcoded credentials and API keys, and businesses that believe there has been a security breach should rotate all credentials and keys without delay. If unusual AI usage, such as spikes in activity, is found, then consider temporarily revoking access and contact your provider.
Charlie Osborne
Contributing Writer
Charlie Osborne is a cybersecurity journalist and photographer who writes for ZDNET and CNET from London. PGP Key: AF40821B See full bio









English (US) ·