NewsMacroHackers Hijack AI Accounts and Servers to Fuel a Booming Cyber Crime Economy

Hackers Hijack AI Accounts and Servers to Fuel a Booming Cyber Crime Economy

Author: CryptoBriefing·

Key Takeaways

  • •LLMjacking involves stealing credentials and API keys for AI platforms and reselling the access on underground marketplaces, typically at 40% to 60% discounts off retail pricing.
  • •In one documented incident, nearly 200,000 API requests were fired through a single compromised corporate account in just two minutes.
  • •Attack chains typically begin with infostealer malware that quietly siphons browser-stored passwords, API keys, and session tokens from infected machines.
  • •CrowdStrike's 2026 Threat Hunting Report recorded an 89% increase in AI-related adversary activity between July 2025 and June 2026, and Google Threat Intelligence reported that average prices for stolen AI accounts more than doubled in 2026.
  • •Detection is difficult because valid stolen API keys generate traffic indistinguishable from legitimate use, and sophisticated operators throttle usage and spread activity across multiple accounts to avoid triggering alerts.
Hackers Hijack AI Accounts and Servers to Fuel a Booming Cyber Crime Economy

A new breed of heist requires no ski mask. Attackers are stealing login credentials and API keys for major AI platforms, then burning through their victims' compute budgets at industrial scale. In one documented incident, nearly 200,000 API requests were fired through a single compromised corporate account in just two minutes.

The practice has acquired a name: LLMjacking. The concept resembles carjacking, except the prize is not a vehicle but access to large language models from providers such as OpenAI, Anthropic, and Google. The stolen access is then flipped on underground marketplaces, typically at discounts of 40% to 60% off retail pricing. Findings from CrowdStrike, Okta, and Google's threat teams point to a maturing underground economy built around AI access.

For victim organizations, the costs are direct: every hijacked request runs on compute the legitimate account holder is billed for, while the stolen access changes hands as a commodity on underground marketplaces.

How the attack pipeline works

The chain typically begins with infostealer malware, a category of lightweight tools designed to quietly siphon browser-stored passwords, API keys, and session tokens from infected machines. With valid credentials for a corporate AI account in hand, attackers can tap the same compute resources the legitimate owner is paying for.

Infostealers are not new, but AI accounts raise the value of what they exfiltrate: a single working API key can unlock metered access to top-tier AI models on someone else's budget, which is exactly what makes these credentials attractive targets.

CrowdStrike's 2026 Threat Hunting Report documents an 89% increase in AI-related adversary activity between July 2025 and June 2026, a figure that spans everything from credential theft to full infrastructure compromise. Separately, Google Threat Intelligence reports that average prices for stolen AI accounts more than doubled in 2026.

The scale of the problem

Okta's security team analyzed a 7 GB dump of infostealer logs from September 2026 and identified hundreds of unexpired tokens tied to AI services. In the same month, autonomous AI-agent campaigns compromised infrastructure across 395 organizations in 48 countries. Stolen access to more than 30 different LLM providers was being resold on underground markets throughout 2026.

The dynamic has precedent: hijacked cloud credentials were previously used to mine cryptocurrency on someone else's infrastructure bill. What has changed is the merchandise — the commodity for sale is now access to leading LLM platforms themselves.

The attacks often mimic legitimate usage patterns, which is precisely what makes them so difficult to detect.

Why detection remains difficult

The core challenge for defenders is that stolen credentials generate traffic that appears legitimate at the protocol level. An API key cannot identify who is holding it: if the request format is correct and the authentication token is valid, the platform processes it.

Traditional anomaly detection can catch volume spikes, such as the nearly 200,000-request burst recorded in the incident cited earlier. More sophisticated operators, however, throttle their usage to stay beneath monitoring thresholds and spread activity across multiple stolen accounts, ensuring that no single account generates enough traffic to trigger alerts.

For security teams and platform operators, the signals worth monitoring are the ones researchers are already tracking: fresh infostealer log dumps like the one Okta dissected, and underground listings offering discounted access to major AI platforms.