The global cybersecurity landscape is currently witnessing a significant shift in the methods employed by threat actors, as traditional resource hijacking evolves to meet the demands of the generative artificial intelligence era. Security experts, including high-level analysts from Google’s Threat Intelligence Group, have issued urgent warnings regarding a burgeoning underground economy centered on the illicit sale of access to large language models (LLMs) and the massive computing power required to run them. This phenomenon, increasingly referred to as "LLMjacking," represents a critical threat to corporate financial stability and data integrity, as cybercriminals pivot from stealing electricity for cryptocurrency mining to seizing expensive AI tokens and API credentials.
Speaking recently with the Financial Times, John Hultquist, chief analyst for Google Threat Intelligence Group, revealed that the cybersecurity unit has documented a "major increase" in LLMjacking activities throughout the 2024–2026 period. This trend is not merely a technical nuisance but a sophisticated financial drain that could cost unsuspecting businesses hundreds of thousands of dollars in unauthorized usage fees while providing attackers with the high-performance tools necessary to launch even more complex cyberattacks.
Understanding the Mechanics of LLMjacking
To understand LLMjacking, one must first look at its predecessor: cryptojacking. For years, cybercriminals utilized malware to hijack the processing power of servers and personal computers to mine cryptocurrency, such as Monero, at the victim’s expense. LLMjacking operates on a similar parasitic logic but targets a much more expensive and modern resource: the API keys and cloud credentials that grant access to advanced AI models like GPT-4, Claude 3.5, and Gemini.
In the contemporary enterprise environment, AI integration is typically managed through API (Application Programming Interface) keys. These keys act as digital "passes" that allow a company’s software to communicate with an AI provider’s servers. Because enterprise accounts often come with high usage limits or "pay-as-you-go" structures to accommodate large-scale operations, a single compromised API key can grant an attacker virtually unlimited access to premium AI compute. The financial burden of this usage is then passed directly to the victimized corporation, often manifesting as "token overspill" charges that fall outside the scope of standard monthly subscriptions.
The Evolution of Resource Hijacking: A Chronology
The transition to LLMjacking is the latest chapter in a decades-long history of digital resource theft. This evolution reflects the changing value of different types of computational output:
- The Botnet Era (Early 2000s – 2010s): Attackers focused on hijacking network bandwidth and CPU cycles to launch Distributed Denial of Service (DDoS) attacks or send massive quantities of spam email.
- The Cryptojacking Boom (2017 – 2022): As the value of Bitcoin and privacy coins soared, attackers shifted their focus to GPU and CPU hijacking for mining. This period saw the rise of browser-based mining scripts and server-side exploits specifically designed to generate digital currency.
- The Generative AI Gold Rush (2023 – Present): With the public release of ChatGPT and subsequent enterprise AI tools, the most valuable commodity in the digital world shifted from "hash rates" to "inference tokens."
- The Surge of LLMjacking (2024 – 2026): Security researchers began identifying dedicated tools and dark web marketplaces specifically designed to scan for, steal, and resell AI API keys. This period marks the professionalization of AI resource theft.
The Underground Economy: Stolen AI at a Discount
The primary driver behind the surge in LLMjacking is the lucrative nature of the underground marketplace. Google’s Threat Intelligence Group has identified various platforms where stolen credentials and API keys are sold to other criminal groups at a fraction of their legitimate cost. According to Hultquist, some traders offer access to premium AI models from companies like OpenAI, Anthropic, and Google for up to 97% off the official market price.
These marketplaces operate with a surprising level of "customer service." Some illicit vendors offer guarantees, promising to provide a new set of compromised credentials if the original account is revoked or closed by the provider’s security team. This "access-as-a-service" model allows lower-tier cybercriminals to utilize powerful AI tools for their own malicious purposes—such as generating convincing phishing emails, writing malware, or automating vulnerability research—without incurring any of the associated costs.
The Financial Toll on Enterprise Organizations
The financial implications of LLMjacking are staggering compared to previous forms of resource theft. While cryptojacking might result in a noticeable but manageable increase in a company’s electricity bill or cloud hosting costs, LLMjacking hits the core of operational budgets.

Data from Sysdig’s Threat Research Team highlights the severity of the problem. Researchers found that once an attacker gains access to a high-tier AI model via stolen cloud credentials, they can rack up astronomical bills in a matter of hours. Sysdig estimates that unauthorized usage can cost businesses approximately $46,000 per day, with some extreme cases exceeding $100,000 in a single 24-hour period. For many mid-sized enterprises, such a sudden and unexpected expense can cause significant liquidity issues and disrupt long-term digital transformation projects.
Furthermore, the damage is not purely financial. As Hultquist points out, this creates an "economic advantage" for the adversary. In the current cybersecurity landscape, both attackers and defenders are turning to AI to gain an edge. However, while defenders are often constrained by budgets and the rising costs of AI tokens, attackers using stolen resources have effectively "zeroed out" their overhead. This allows them to scale their operations to an unprecedented degree, using the victim’s own money to fund the tools used against them.
Methods of Compromise: How Credentials Are Lost
Cybercriminals employ a variety of tactics to secure the credentials necessary for LLMjacking. These methods range from low-tech social engineering to sophisticated technical exploits:
- Phishing and Social Engineering: This remains the most common entry point. Employees are tricked into entering their corporate login credentials or API keys into fraudulent websites.
- Hardcoded Credentials in Public Repositories: Developers often accidentally leave API keys embedded in code that is pushed to public platforms like GitHub. Specialized "secret-scanning" bots used by criminals can find these keys within seconds of them being posted.
- Data Breaches and Insider Threats: Stolen databases from previous breaches often contain reusable password combinations. Additionally, disgruntled or compromised employees may intentionally leak API keys for profit.
- Misconfigured Cloud Instances: Improperly secured cloud storage buckets or misconfigured server settings can expose internal configuration files that contain sensitive access tokens.
Defensive Strategies and Industry Responses
As the threat of LLMjacking grows, security experts are urging organizations to move beyond traditional perimeter defense and adopt a more granular approach to AI security. The "Least Privilege" or "Zero Trust" framework is increasingly seen as the gold standard for protecting AI assets. Under this model, no user or application is given broad access to AI resources by default; instead, access is granted only for specific tasks and for a limited duration.
Security professionals recommend the following immediate actions for businesses:
- Eliminate Hardcoded Keys: Organizations must implement automated scanning tools to ensure that no API keys are stored in plaintext within source code or configuration files. Using secret management services (like AWS Secrets Manager or HashiCorp Vault) is essential.
- Continuous Monitoring and Rate Limiting: Businesses should set strict usage quotas and alerts for their AI accounts. Any sudden spike in token consumption should trigger an automatic temporary suspension of the API key until the activity can be verified.
- Regular Credential Rotation: Much like passwords, API keys should be rotated on a frequent, scheduled basis. This limits the "window of opportunity" for an attacker if a key is compromised.
- Enhanced Employee Training: Phishing simulations should be updated to include scenarios specifically targeting AI platform credentials, moving beyond simple bank or email-themed lures.
- Audit and Patch Management: Security teams must be given the resources to conduct frequent audits of their AI integrations and ensure that all software interacting with these models is fully patched against known vulnerabilities.
Broader Implications and the Future of AI Security
The rise of LLMjacking signifies a broader shift in the "weaponization" of AI. As the technology becomes more deeply integrated into the global economy, the resources that power it—compute and data—become primary targets for theft and sabotage. The fact that cybercriminals can now sustain an "economic advantage" by using stolen tokens suggests that the gap between attacker capabilities and defender resources may continue to widen.
Furthermore, there is an emerging concern regarding the "poisoning" of AI models. While LLMjacking currently focuses on resource theft, the same unauthorized access could eventually be used to inject malicious data into a company’s private AI training sets, leading to biased outputs or security backdoors.
In response to these threats, AI providers like OpenAI and Google are working to enhance their own security layers, offering more robust logging features and anomaly detection to help enterprise clients spot unauthorized usage. However, the "shared responsibility" model of cloud computing remains in effect: while the provider secures the infrastructure, the client remains responsible for securing the keys to the kingdom.
In conclusion, LLMjacking is a clear signal that the "wild west" era of generative AI adoption is coming to an end, replaced by a more dangerous period where AI resources are treated as high-value currency. For businesses, the cost of failing to secure these credentials is no longer just a matter of data privacy—it is a direct threat to the bottom line. As the underground economy for stolen AI power continues to mature, the ability to monitor, manage, and protect API access will become a defining characteristic of a resilient modern enterprise.
