Skip to content
Breaking:

Rise in LLMjacking Exposes Enterprises to Costly AI Account Thefts

Cybercriminals are stealing corporate API keys and credentials to access frontier models, driving illicit resale markets and unexpected enterprise bills.

By The Company Wire3 min read
Share
Google — Rise in LLMjacking Exposes Enterprises to Costly AI Account Thefts
Google — Rise in LLMjacking Exposes Enterprises to Costly AI Account Thefts. Photo: ZDNET.

Cybercriminals are increasingly targeting enterprise artificial intelligence accounts to siphon computing power and run workloads on corporate tabs, according to threat researchers. The tactic, known as LLMjacking, mirrors cryptojacking by hijacking paid resources—in this case, high-limit API keys and enterprise subscriptions—rather than paying for tokens directly.

The growth of illicit AI access was detailed in a report by ZDNET (https://www.zdnet.com/innovation/llmjacking-business-ai-bill-cost-how-to-stop/), drawing on comments by John Hultquist, chief analyst for the Google Threat Intelligence Group, in an interview with the Financial Times. Hultquist reported that Google's cybersecurity unit observed a major increase in LLMjacking activity across 2026 as organizations scaled up their use of generative AI models.

Attackers typically obtain authorized API keys or login credentials through corporate phishing, data breaches, unpatched software vulnerabilities, or insider threats. Once inside, bad actors can exploit accounts that feature high usage limits or uncapped token billing, leaving target organizations responsible for the resulting overage charges.

Compromised credentials and keys are also actively traded on underground cybercrime markets. According to Hultquist, researchers have identified illicit access to models from providers such as Anthropic, Google, and OpenAI offered at discounts of up to 97%, with some sellers providing replacement guarantees if an account is revoked.

The financial exposure for enterprise victims can escalate rapidly. Estimates from Sysdig's Threat Research Team indicate that unauthorized token usage on top-tier models can cost organizations between $46,000 and more than $100,000 per day. In addition to direct monetary costs, Hultquist noted that attackers gain an economic advantage by running malicious operations on victim-funded AI resources while legitimate defenders bear the high compute expenses.

To mitigate the risk of account compromise, security analysts recommend implementing robust employee phishing awareness, running regular configuration audits, and patching network vulnerabilities promptly. Organizations are also advised to avoid hardcoding API keys, enforce least-privilege access frameworks, rotate credentials immediately after any suspected breach, and monitor for anomalous usage spikes.

Sources

  1. ZDNET

Company: Google

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.