Hackers Are Targeting AI Accounts and Corporate Cloud Computing Resources
The rapid growth of artificial intelligence has created a new cybersecurity target: access to expensive AI services and the computing infrastructure needed to run them.
Cybersecurity researchers are reporting an increase in attacks in which criminals steal credentials for paid AI services, obtain API keys, or compromise corporate cloud environments and use them for their own artificial intelligence workloads.
The activity, sometimes described as “LLM jacking,” allows attackers to shift the cost of AI usage onto victims. Instead of paying for expensive models and high-performance computing infrastructure themselves, attackers attempt to use accounts, cloud resources, and computing capacity belonging to other organizations.
What Is LLM Jacking?
LLM jacking refers to the unauthorized use of large language model services or computing resources after attackers obtain access to someone else's account, API credentials, or cloud environment.
Google's Threat Intelligence Group has highlighted the activity as an emerging concern as demand for advanced AI services continues to grow.
According to reporting cited in the supplied information, Google Threat Intelligence analyst John Hultquist told the Financial Times that LLM jacking activity has increased during 2026.
The underlying motivation is relatively straightforward: advanced AI services can be expensive, while high-performance computing infrastructure can require substantial resources. Compromising someone else's access can allow attackers to reduce or avoid those costs.
Stolen AI Accounts Are Becoming a Cybercrime Commodity
One aspect of the problem involves stolen credentials for commercial AI services.
Attackers can obtain login information and then sell access through underground marketplaces and forums. According to Google's threat intelligence reporting, underground communities have seen increased activity involving both buyers and sellers of AI accounts.
The supplied report also indicates that the average price of some stolen AI accounts has more than doubled compared with the previous year.
Services and tools associated with AI assistants and coding are among the types of accounts reportedly being targeted.
Some Sellers Offer Replacement Access
The underground market is also becoming more organized.
Hultquist reportedly described sellers offering guarantees in which buyers receive replacement credentials if an initially compromised account is subsequently blocked by the service provider.
This creates a business model around unauthorized AI access: attackers obtain accounts, sell access, and potentially replace credentials when providers detect and disable compromised accounts.
For AI companies, this creates another challenge because blocking individual accounts may not completely eliminate the underground market.
API Keys Create Another Potential Entry Point
AI developers frequently use API keys to connect applications with AI services.
These keys function as authentication credentials that allow software to communicate with an AI provider. Depending on how an application is configured, compromised credentials could allow unauthorized users to consume paid AI services or potentially reach other connected resources.
Google has previously identified malware designed to search for configuration files associated with AI coding tools.
If sensitive credentials are stored insecurely in these files and subsequently stolen, attackers may be able to use the credentials for unauthorized activity.
This makes protecting API keys an important part of AI security.
Corporate Cloud Infrastructure Can Also Be Misused
The threat goes beyond individual AI accounts.
Cybersecurity investigations have also uncovered incidents in which attackers compromised corporate cloud environments and used the computing infrastructure for AI-related workloads.
In one incident investigated by Mandiant in April, attackers reportedly gained access to a corporate cloud environment through an exposed GitHub personal access token.
After gaining access, the attackers deployed AI-related services and activated high-performance computing resources.
The investigation also found activity involving requests for increased usage limits for NVIDIA RTX 6000 GPUs, according to the information provided.
If attackers successfully use cloud computing resources in this way, the victim organization may face unexpected infrastructure costs while its computing capacity is consumed by unauthorized workloads.
Why Cloud-Based AI Abuse Can Be Difficult to Detect
One challenge is that legitimate AI workloads can already generate substantial increases in computing demand.
Organizations adopting AI may experience rapidly changing patterns of GPU usage, cloud spending, and computational workloads. As a result, an unusual increase may initially appear to be part of normal business growth.
This can create a window in which unauthorized workloads remain unnoticed.
Google Threat Intelligence has also reported activity in which compromised cloud environments were used to deploy publicly available AI models.
The reported technique can allow attackers to run AI workloads using a victim's infrastructure rather than relying entirely on commercial AI APIs, potentially making some conventional forms of API monitoring less useful.
Cybersecurity Teams Need to Monitor More Than Login Activity
The emerging threat means organizations need to consider AI infrastructure as part of their broader security strategy.
Traditional account protection remains important, but companies also need visibility into how cloud resources are being consumed.
Security teams can monitor for warning signs such as:
Unexpected increases in GPU utilization
Sudden cloud computing cost increases
New AI-related services or containers
Unusual API activity
Newly created or modified access credentials
Unexpected changes to GPU quotas
Cloud workloads appearing in unfamiliar regions
Unknown applications accessing AI services
Suspicious GitHub or developer credentials
These indicators do not automatically prove that an organization has been compromised, but they can help security teams investigate unusual activity more quickly.
Protecting AI Accounts and API Credentials
Organizations using commercial AI services and cloud-based AI infrastructure can reduce exposure by treating AI credentials as sensitive security assets.
Important security practices include:
Use Strong Authentication
Multi-factor authentication can provide an additional layer of protection if passwords are compromised.
Where supported, organizations should consider stronger authentication methods and carefully control administrative access to AI and cloud platforms.
Protect API Keys
API keys should not be stored in public repositories or exposed in application code.
Organizations can use secure secrets-management systems and regularly rotate credentials where appropriate.
Review Cloud Permissions
Cloud accounts should follow the principle of least privilege, giving users and applications only the permissions they actually need.
Unused credentials and excessive permissions can increase the potential impact of an account compromise.
Monitor GPU Usage
GPU resources can be particularly valuable to attackers conducting unauthorized AI workloads.
Monitoring GPU utilization, quotas, and cloud spending can help identify activity that differs from expected business patterns.
Investigate Unexpected AI Workloads
Organizations should maintain an inventory of approved AI services and workloads.
When an unfamiliar model, container, or AI-related process appears in a corporate environment, security teams should investigate its origin and purpose.
AI Security Is Becoming Part of Cloud Security
The growing use of artificial intelligence means cybersecurity teams are dealing with a new combination of risks.
Previously, attackers might have been primarily interested in stealing data, disrupting services, or gaining access to corporate networks. AI infrastructure introduces another incentive: the computing resources themselves can have significant economic value.
A compromised cloud account may provide access to GPUs, storage, networking, and other infrastructure that can be used for unauthorized AI workloads.
Likewise, a stolen AI subscription or API credential can allow criminals to shift the cost of AI usage to someone else.
The Cost May Go Beyond the AI Bill
Unauthorized AI usage can create several consequences for victims.
Organizations could face unexpected cloud charges, exhausted service quotas, reduced computing availability, or disruption to legitimate AI projects.
A compromised developer credential could also create additional security concerns if the same credential provides access to other systems.
For that reason, an unusual AI-related bill should not simply be treated as a financial problem. It can potentially be an indicator that credentials or cloud infrastructure require investigation.
Conclusion
Artificial intelligence is becoming a valuable resource not only for businesses and developers but also for cybercriminals looking for ways to obtain computing power without paying the associated costs.
Reports from Google Threat Intelligence and Mandiant indicate that attackers are targeting AI accounts, API credentials, and corporate cloud infrastructure for unauthorized AI activity.
The rise of these attacks highlights an important security lesson: AI access should be protected with the same seriousness as other valuable digital infrastructure.
Organizations can reduce their exposure by securing credentials, limiting cloud permissions, monitoring GPU and AI usage, protecting API keys, and investigating unexpected changes in computing activity.
As AI adoption continues to expand, security teams will increasingly need to understand not only what data attackers want, but also which computing resources they may want to steal.
Cybersecurity note: The examples described in this article are based on reported threat-intelligence findings. Specific indicators do not necessarily mean that every organization experiencing unusual AI or cloud usage has been compromised; investigation is required to determine the cause.
0 Comments