LLM-jacking emerges as a blowing form of AI-enabled cybercrime, with underground prices doubled over 2026 | #cybercrime | #infosec


LLM jacking is a form of cybercrime where hackers hijack AI services credentials to access computing and AI resources without authorisation

LLM jacking is emerging as a distinct form of cybercrime where hackers steal access to artificial intelligence services or compromise cloud infrastructure to use computing and AI resources without authorisation. It consist in a cyberattack in which threat actors steal cloud account credentials to access an organization’s hosted large language models (LLMs). Recent cases like Amazon Bedrock or Google Vertex AI underline the emergence of an AI-specific criminal economy in which access to AI infrastructure, credentials and compute has itself become a commodity.

In short, it is a form of cloud resource hijacking where threat actors steal or leak valid credentials (such as IAM access keys) to illegally run and monetize paid foundation model inference at the victim’s financial expense.

In its September 2026 Cyber Brief, CERT-EU provides a useful European angle that similarly identified a surge in LLM-jacking, highlighting the theft and resale of access to premium AI tools and the hijacking of cloud servers for unauthorised workloads. The development illustrates how AI infrastructure is becoming not only a tool used by cybercriminals, but itself a target and commodity within the cybercrime ecosystem.

Compromised credentials can provide three forms of value simultaneously: access to computing resources, access to AI capabilities and an additional layer of attributional cover. Average underground prices for stolen AI accounts have more than doubled during the year, according to Google Threat Intelligence Group (GTIG) latest report.

GTIG reports identifies a growing underground market for AI-related accounts and credentials, alongside an increasing number of intrusions aimed at hijacking enterprise cloud resources for AI workloads. During 2026, both demand for and supply of AI-related accounts increased on underground forums, with particularly strong demand for credentials providing access to premium models such as Claude and Gemini, as well as autonomous coding environments such as Cursor Pro and Devin. The report, that indicates that threat actors are moving beyond basic use of LLMs to agentic workflows along with legitimate enterprise, documented an autonomous credential raid completed within six hours. It also exposes an April 2026 intrusion in which a threat actor obtained access to a cloud environment through an exposed personal access token and used it to deploy unauthorised AI infrastructure and scale high-performance computing resources, leaving the victim to bear the associated costs.

Anthropic has similarly reported that compromised API keys and session tokens are increasingly being treated as valuable criminal assets, with brokers reselling access and malicious actors using stolen credentials to run their own workloads.

Meanwhile, the Okta Threat Intelligence team released an in-depth study highlighting how session token theft and info-stealer malware are actively driving LLM-jacking across enterprises. As organizations integrate expensive generative AI models and deployment platforms into their workflows, attackers are treating stolen AI API credentials as liquid commodities. Okta traced 44,791 session tokens in a single 7GB infostealer dump, underscoring the scope of the surge.

Mandiant documented cases where attackers hijacked developer environments to integrate large language models (LLMs) directly into live, compromised servers to debug and optimize offensive tools in real time, what is called In-Situ AI Co-Debugging–the attacker used an AI coding chatbot and a set of instructions to plan, build and execute a mass credential-harvesting campaign in less than six hours. Besides, Mandiant observed a financially motivated threat actor compromise an organisation’s cloud infrastructure and deploy an autonomous, multi-agent attack framework.

Why does it matter?

This development forms part of a wider transformation of the AI-enabled cybercrime ecosystem. AI services are becoming integrated into established criminal markets alongside stolen credentials, malware, cloud infrastructure and illicit AI-as-a-service offerings.

At the same time, attackers are targeting the configurations and integrations surrounding AI systems, including API keys, agent environments, proxies, coding assistants and other tools that connect models to organisational infrastructure. CERT-EU’s September assessment illustrates this broader convergence: alongside LLM-jacking, it recorded attacks involving the theft of AI API keys, autonomous AI agents and the compromise of systems used to support AI workloads. The result is an expanding attack surface in which AI credentials and infrastructure can function simultaneously as targets, resources and enablers of further attacks.

LLM-jacking illustrates an important shift in the economics of AI-enabled cybercrime. The value of AI is no longer limited to the information or capabilities that models generate: access to the underlying compute, models, APIs and agentic infrastructure is itself becoming a strategic cyber asset.

More broadly, the development suggests that the growing integration of AI into cloud environments is creating a new intersection between AI security, cloud security and cybercrime, with implications for accountability, attribution, incident response and the emerging governance of AI-enabled cyber operations.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!



Click Here For The Original Source.

——————————————————–

..........

.

.