Hackers are hijacking AI accounts and servers in large numbers to seize computing power

📅 2026-09-28

Abstract:

Illegal access to AI models and computing power is quickly becoming the hottest commodity in the cybercriminal underworld. Hackers try to exploit expensive large language models for blackmail, warfare, and espionage. John Hultquist, principal analyst at Google Threat Intelligence Group, said the cybersecurity group has seen a significant increase in so-called "LLM-jacking" attacks this year, which include selling stolen login credentials for public AI tools and groups stealing computing resources to run their own models for free.

03_ThreatIntelligenceWebsiteBannerIdeas_BA.max-2600x2600.png

“What we’re seeing in the underground market is a growing economy around AI access,” said Hultquist, a 20-year cybersecurity veteran.

Hultquist warned that obtaining expensive AI resources at low cost will give cyber attackers a financial advantage over their targets, who also need to use these AI tools to protect themselves.

He said: "At the end of the day, all of these actions give them some kind of economic or efficiency advantage over us because they can actually obtain these tokens at a much cheaper price."

Researchers from Google’s Threat Intelligence Unit have discovered that some marketplaces on the dark web are selling access to AI models from companies such as Anthropic, Google and OpenAI at discounts of up to 97%. The most advanced versions of ChatGPT and Claude’s AI subscription services cost up to $200 per user per month.

Given that AI Labs monitors for signs of such abuse, some sellers are even offering "guaranteed access," promising new login credentials for free if the original account is banned, Hultquist said.

In other cases, criminal gangs and state-backed organizations hack into servers hosted by companies in the cloud and deploy their own AI models to run on target systems. This approach is similar to previous attempts by threat actors to compromise third-party computers for cryptocurrency mining.

AI is already used by "all threat actors," Hultquist said, adding that AI tools must become an integral part of cybersecurity systems in the future. In Anthropic's most recent quarterly report on AI abuse, the company found that threat actors from more than 20 countries, including the United States, the United Kingdom, and Yemen, had attempted to use its Claude tool for malicious activity.

He said: "Anyone who thinks that AI is just a fad and wants it to pass away will one day wake up and find that they have been overwhelmed. They will face more security incidents, more alerts, and more attacks than ever before. We must take care of our own affairs now."

Hultquist warned that as more and more large enterprises seek to deploy customized AI models on their own servers rather than rent computing power from cloud service providers, these systems themselves will also become targets of attacks and must be closely protected. "If you're paying for computing power, and computing power can be very expensive...then that becomes a very attractive potential resource in the eyes of threat actors."

Hultquist also said that now is the best time for hackers to "infiltrate" target accounts and computer servers, because companies are still figuring out how much AI resources they will use.

He said: "You may think that a sudden and large increase in computing power usage is completely normal because you have just deployed so much AI infrastructure. This does give some people an opportunity to hide in the noise."

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet