AI accounts and computing power are becoming the hottest commodities on the cybercrime black market. Hackers have set their sights on expensive large language models, using them for extortion, cyber warfare, and espionage.
Recently, John Hultquist, chief analyst at Google Threat Intelligence Group, said in an interview with the UK's Financial Times that since the start of this year, hacker attacks targeting AI accounts and computing resources have grown significantly, and a new attack technique known as "LLM-jacking" is taking shape across the cybercrime underworld.
Dark web marketplaces are selling access to AI models from companies such as Anthropic, Google, and OpenAI at discounts of up to 97%. At the same time, criminal groups and state-backed hacker organizations are breaking into corporate cloud servers and deploying their own AI models to freeload on computing power, in a manner strikingly similar to the earlier practice of hijacking other people's machines for crypto mining.
"What we're seeing in the underground market is a growing economy around AI access," said the analyst, who has 20 years of experience in cybersecurity.
Dark web discounts reach 97%, turning AI account trading into a gray industry
According to researchers at Google Threat Intelligence Group, dark web marketplaces are selling access to AI models from companies such as Anthropic, Google, and OpenAI at discounts as high as 97%.
For context, subscriptions to the most advanced versions of ChatGPT and Claude can cost up to $200 per user per month.
More notably, because AI companies actively monitor for signs of abuse, some sellers have even introduced a "guaranteed access" service, promising to issue new credentials free of charge if the original account is banned. This mechanism makes the black-market supply chain operate more reliably.
Hijacking cloud servers to freeload on computing power
Beyond reselling accounts, another type of attack is more direct. Hultquist revealed that some criminal groups and state-backed hacker organizations are breaking into corporate cloud-hosted servers and deploying their own AI models to run directly on the target systems, with the victims footing the bill while the attackers use the computing power.
This follows the same logic as the early days when hackers broke into other people's machines to mine cryptocurrency.
Defenders face a cost asymmetry dilemma
Hultquist pointed out that the danger of this attack model lies not only at the technical level, but also in the economic imbalance.
"Ultimately, these behaviors give them an economic or efficiency advantage, because they can obtain this computing power at a much lower cost, while we have to pay full price to defend against it," he said.
Anthropic's latest quarterly AI abuse report shows that threat actors attempting to use its Claude tool for malicious activities have been found in more than 20 countries, including the United States, the United Kingdom, and Yemen.
Hultquist was blunt about it: "Every threat actor is using AI."
A new risk window: the early days of AI deployment are the best time to hide
As more large enterprises choose to build their own servers to deploy customized AI models rather than renting computing power from cloud service providers, these internal systems will also become new attack targets.
Hultquist warned: "If you are paying for computing power, and it can be very expensive, then it becomes a major potential resource in the eyes of threat actors."
He also noted that the stage when enterprises have just completed deploying AI infrastructure is precisely the best time for hackers to sneak in.
You may think a sudden sharp increase in computing usage is completely normal, because you have just brought in a bunch of AI infrastructure. This gives attackers a real opportunity to hide in the noise.
He concluded with a warning: "Anyone who thinks AI is just a passing fad and wants to wait for it to blow over will one day find themselves drowning. They will encounter more incidents, more alerts, and more attacks than ever before. We must get our own house in order right now."
Comments