LLMjacking can quickly open your business’s AI bill – how to stop it

ZDNET’s key takeaways

  • Security experts warn of a growing market in stolen AI account credentials.
  • LLMjacking, the illegal use of AI resources, is a popular criminal trend in 2026.
  • Businesses must monitor and protect their accounts. Here’s how.

Security experts warn that it’s not just artificial intelligence (AI) that’s bad that we need to worry about – there’s also a booming underground economy for selling access to your AI models and computing power.

Speaking to the Financial Times, John Hultquist, chief analyst for Google Threat Intelligence Group, said that the cybersecurity unit saw a “big increase” in what is known as LLMjacking over 2026, a trend that could cost businesses dearly.

What is LLMjacking?

If cryptojacking came to mind, you are on the right track. While cryptojacking describes stealing computing power to mine illegal cryptocurrency, LLMjacking is the AI ​​equivalent: using AI power and resources that don’t belong to you.

Also: OpenAI’s Dots: How OpenClaw declawed – for $200/mo ChatGPT Pro User

In the cybercriminal world, that means trying to secure credentials or API keys that give criminals authorized access to business AI accounts, which often have high usage limits, or potentially none at all—with token overplay outside of typical subscription fees.

Cybercriminals can obtain username and password combinations or API keys by gaining access to a corporate network, stealing them via phishing, data breaches, vulnerabilities or insider threats. This gives cybercriminals the opportunity to use an AI model without paying for the tokens themselves, for reasons such as:

  • Perform high-level computing tasks that require tokens
  • Exploit computing resources to execute their own malicious AI models or tasks
  • Extract and steal sensitive corporate information that is fed into a victim’s model
  • Poisoning training datasets, ruining output

Once stolen, credentials and API keys can also be sold underground to other cybercriminal groups.

The increasing cost of LLMjacking

As AI models offered by organizations including OpenAI and Anthropic continue to advance in sophistication, capability and capability, they will need more computing power.

The more power you need, the more tokens you need to buy – or the higher the level of subscription you need to buy.

For operating companies, inflated bills caused by unauthorized users can add up quickly, with Sysdig’s Threat Research team estimating the cost to be around $46,000 and even over $100,000 per day on top-tier models.

‘Guaranteed’ access to dirt-cheap AI models

Combine the raw power of AI and exposed credentials that can be easily purchased online, and you can see why LLMjacking is exploding in popularity.

As well: Who is responsible for catching rogue AI agents? You are

According to Hultquist, the security team has seen illegal access to AI models offered by companies including Anthropic, Google, and OpenAI for up to 97% discount, and some merchants even guarantee continued access if a compromised account is revoked or closed.

The financial damage is not limited to the victims of LLMjacking. As the analyst points out, by using stolen AI power, cybercriminals now gain an “economic advantage” to carry out attacks using AI resources paid for by others, while defenders are limited by rising token costs.

How companies can defend themselves

AI accounts are a hot commodity, and it’s up to the owner to mitigate the risk of compromise – especially with such high financial consequences at stake.

Phishing is, and probably always will be, one of the main causes of account theft or exploitation, so implementing valuable training and awareness programs beyond an annual tick-box exercise is one of the first ways businesses can protect themselves.

As well: Why Phishing Training Won’t Stop Your Employees From Clicking Scam Links

Misconfigured instances, settings and exposed data can all lead to LLMjacking, which is why security teams should be given the time and capacity to run regular audits – as well as regular patch cycles to fix unpatched vulnerabilities that provide unauthorized network access.

Another critical way to defend your organization against LLMjacking is to adopt the principles of least privilege. Least privilege, or zero trust, is a setting in which employees only have access to the resources they need for their jobs, and only when they need them, which can reduce the risk of admin-level accounts being exploited for malicious purposes.

Finally, avoid hardcoded credentials and API keys, and businesses that believe there has been a security breach should rotate all credentials and keys without delay. If unusual AI usage, such as spikes in activity, is found, consider temporarily revoking access and contact your provider.

Leave a Comment