Security experts have raised concerns about a growing market for stolen account credentials linked to artificial intelligence (AI), a threat known as "LLMjacking." According to John Hultquist, chief analyst at the Google Threat Intelligence Group, there has been a "significant increase" in LLMjacking cases in 2026. This trend could pose serious financial risks for businesses, as cybercriminals exploit AI resources for their own gain.
LLMjacking is similar to cryptojacking, where hackers steal computing power to mine cryptocurrencies. In the context of AI, LLMjacking involves unauthorized access to AI models and computing resources through stolen usernames, passwords, or API keys. Cybercriminals can obtain these credentials by infiltrating a company's network, using phishing attacks, exploiting data breaches, or taking advantage of system vulnerabilities. Once they have these credentials, attackers can run resource-intensive tasks, deploy harmful AI models, extract confidential information, or manipulate training datasets. These stolen identifiers can also be sold on the dark web.
As AI models from companies like OpenAI and Anthropic become more advanced, they require greater computing power, which drives up the cost of using these models. For large organizations, the financial impact of unauthorized access can be substantial, with daily costs estimated between $46,000 and over $100,000 for high-end AI systems. Some cybercriminals even offer discounted access to AI models, sometimes as low as 3%, with promises of uninterrupted use even if an account is suspended or closed.
The economic consequences of LLMjacking extend beyond the victims. Cybercriminals benefit by using AI resources paid for by others, while legitimate users face rising costs. To protect against LLMjacking, businesses should focus on training employees to recognize and avoid phishing attempts, which are a leading cause of account theft. Regular system audits and updates are essential to close security gaps that could be exploited. Implementing the "zero trust" principle—granting users only the minimum access needed—can reduce the risk of administrator-level accounts being misused. Companies should avoid embedding sensitive information like API keys directly into systems and should renew these credentials if a security breach is suspected. If unusual AI activity is detected, access should be temporarily blocked, and the service provider should be alerted.
Cybersecurity experts warn of rising threat of LLMjacking in 2026
AI-rewritten from original reportingHow it works
llmjackingai-securitycybercrimecybersecurityai-costsphishing



