Every score is worked out from the vendor's own pages · How we score →Disclosure
SAASINSPECTOR
Sep 30, 2026

LLMjacking is draining AI budgets. Here is how to stop it

Stolen credentials for OpenAI, Anthropic and Google models are being sold at up to 97% off, and the bill lands on the victim.

LLMjacking is draining AI budgets. Here is how to stop it

A growing underground economy sells access to other people's AI accounts. Cybercriminals go after credentials and API keys that give them authorized access to business AI accounts, then use that access or sell it on, so the victim company gets the bill.

John Hultquist, chief analyst for Google Threat Intelligence Group, told the Financial Times that his team has seen a "major increase" in LLMjacking over 2026. The name mirrors cryptojacking, where attackers steal computing power to mine cryptocurrency. LLMjacking applies the same idea to AI power and resources that do not belong to the attacker.

How stolen AI credentials are obtained and sold

Attackers can get username and password combinations or API keys by gaining access to a corporate network, or through phishing, data breaches, vulnerabilities and insider threats. With working credentials they can use an AI model without paying for the tokens themselves, or sell the credentials to other criminal groups. Hultquist's team has spotted illicit access to models from companies including Anthropic, Google and OpenAI offered for up to 97% off, and some traders even guarantee ongoing access if a compromised account is revoked or closed.

The financial damage LLMjacking causes at scale

Business AI accounts often have high usage limits, or potentially none at all, with token overspill charged outside the typical subscription cost. For enterprise companies, the inflated bills from unauthorized users can climb quickly: Sysdig's Threat Research Team estimates costs of around $46,000 per day on top-tier models, and over $100,000 per day in some cases. The damage is not limited to victims. Hultquist points out that stolen AI power gives cybercriminals an "economic advantage" in carrying out attacks, while defenders are constrained by rising token costs.

A line of people passing glowing boxes hand to hand, like stolen access being sold on down a chain.
A line of people passing glowing boxes hand to hand, like stolen access being sold on down a chain.

Practical steps to protect your API keys and AI accounts

ZDNET names several measures for any business paying for AI access. First, run phishing training and awareness programs that go beyond an annual tick-box exercise, since phishing is one of the main causes of account theft. Second, give security teams the time and capacity for frequent audits, because misconfigured instances, settings and exposed data can all lead to LLMjacking, and keep up regular patch cycles to fix vulnerabilities that could allow unauthorized network access. Third, adopt least privilege, also called zero trust, so employees have access only to the resources they need for their work and only when they need them. This reduces the risk of admin-level accounts being exploited. Fourth, avoid hardcoded credentials and API keys.

What to do if you suspect a breach has already happened

A business that believes there has been a security breach should rotate all credentials and keys without delay. If you find unusual AI usage, such as spikes in activity, consider temporarily revoking access and contact your provider. Because some traders guarantee continued access after a compromised account is closed, closing a single account may not be enough, which is why the advice is to rotate all credentials and keys rather than only the one you suspect.

Sources
Tools mentioned