LLM Jacking: The Emerging Cyber Threat Targeting AI Resources

An Overview of LLM Jacking

It’s fair to say that cybercriminals have noticed how AI has quickly become a valuable enterprise resource. Organizations now spend significant amounts on access to Large Language Models (LLMs), AI platforms, cloud computing, GPUs, APIs, and specialized AI development tools. Malicious actors increasingly want access to those same resources without paying for them.

This emerging threat, known as LLM jacking, involves cybercriminals stealing access to AI services or compromising cloud architecture security to use the victim’s computing resources, AI subscriptions, or model access for their own purposes.

Google Threat Intelligence Group (GTIG) reported a surge in LLM jacking incidents during 2026 (1), while CERT-EU highlighted the trend in its October 2026 Cyber Brief (2). The activity demonstrates an important shift: AI infrastructure itself is becoming a target, a commodity, and a source of criminal profit.

What Is LLM Jacking?

LLM jacking is the unauthorized use of someone else’s access to AI models, services, or computing infrastructure. The attack can take several forms. A cybercriminal may:

  • Steal credentials for premium AI platforms.
  • Compromise API keys belonging to developers.
  • Take over cloud accounts with access to AI services.
  • Hijack cloud computing resources to run unauthorized AI workloads.
  • Steal AI-related configuration files containing credentials or endpoints.
  • Resell stolen AI accounts through underground marketplaces.

The concept resembles cryptojacking, where attackers secretly use compromised computing resources to mine cryptocurrency. With LLM jacking, however, the stolen resource is AI capability, such as model access, GPU capacity, API quotas, or cloud infrastructure.

Why Are Cybercriminals Targeting LLMs?

AI services can be expensive and computationally demanding. Premium AI accounts, API access, and high-performance cloud infrastructure can give threat actors capabilities that would otherwise require substantial financial investment.

GTIG reported that demand for stolen AI account credentials on the dark web increased in 2026. The group also observed growing demand for credentials associated with major AI platforms and autonomous coding environments, with average marketplace prices for some accounts more than doubling during the year.

The result:

A new cybercrime economy built around unauthorized access to AI

How Does an LLM Jacking Attack Work?

An LLM jacking operation typically begins with a credential or infrastructure compromise.

  1. Attackers obtain access: Threat actors may steal credentials through infostealer malware, phishing, credential theft, exposed secrets, compromised developer environments, or previously breached accounts. GTIG observed infostealers specifically targeting configuration files associated with AI coding assistants. Some of these files can contain API keys or custom model-routing endpoints that provide access to paid AI resources.
  2. Attackers identify valuable AI resources: Once inside an environment, attackers look for AI APIs, cloud projects, GPU capacity, AI development tools, model endpoints, credentials, and other resources they can monetize.
  3. Attackers establish unauthorized workloads: The attacker may then provision computing resources, deploy AI infrastructure, create accounts or service identities, or redirect existing resources toward unauthorized workloads.
  4. Attackers monetize the access: The stolen access can be used directly, sold to other criminals, or leveraged to support broader cyber operations.

This makes LLM jacking particularly concerning because the victim may initially see only an unexpected increase in cloud usage or AI consumption.

A Real-World Example of LLM Jacking

Google’s 2026 threat research (1) provides a particularly revealing example:
In an incident investigated by Mandiant in April 2026, a threat actor gained access to a victim’s cloud environment through an exposed GitHub Personal Access Token. The attacker subsequently deployed unauthorized AI infrastructure and expanded high-performance computing resources.

According to GTIG, the attacker created a rogue service account with elevated privileges, searched cloud data for additional credentials, deployed containerized AI infrastructure, enabled generative-AI services, requested increased GPU quotas, and launched additional high-performance compute instances to sustain unauthorized AI workloads.

This example illustrates why organizations should not treat LLM jacking as merely an AI-account problem. A successful attack can escalate into a broader cloud security incident involving identity theft, privilege escalation, infrastructure abuse, data exposure, and financial loss.

What Are the Business Risks of LLM Jacking?

LLM jacking creates several risks for organizations:

  • Financial losses: Unauthorized AI workloads can generate significant cloud and API bills. An attacker who gains access to high-performance computing resources can rapidly increase consumption.
  • Data exposure: Compromised AI environments may provide access to prompts, datasets, source code, model configurations, proprietary research, or other sensitive information.
  • Credential compromise: AI credentials can provide attackers with another pathway into an organization’s broader cloud or development environment.
  • Abuse of organizational infrastructure: Attackers can exploit a compromised infrastructure to conduct malicious operations, potentially resulting in reputational, legal, and operational consequences for the victim organization.
  • Intellectual property theft: AI systems themselves can contain valuable proprietary models, code, research, prompts, and datasets. GTIG reported an increase in targeting of proprietary AI research and models across sectors, including healthcare, government, and media.

How Can Enterprises Defend Against LLM Jacking?

Organizations should embrace a culture of security that treats AI resources as part of their overall cybersecurity architecture. Consider these crucial steps:

  • Secure AI credentials and secrets: Never embed API keys or cloud credentials in source code or configuration files unnecessarily. Store secrets in appropriate secrets-management systems, rotate them regularly, and revoke credentials that may have been exposed.
  • Strengthen identity and access management: Enforce least-privilege principles to AI services, cloud accounts, service accounts, APIs, and developer tools. Use phishing-resistant authentication where appropriate and continuously review privileged identities.
  • Monitor AI and cloud consumption: Security teams should establish baselines for normal AI and cloud usage. Unexpected GPU consumption, unusual API activity, new AI services, unexplained quota increases, or activity from unfamiliar locations can indicate compromise.
  • Protect developer environments: AI coding tools have become an increasingly important part of software development. Organizations should monitor their configurations, dependencies, extensions, secrets, and API integrations just as they would other critical developer infrastructure.
  • Control cloud provisioning: Restrict who can create high-performance compute instances, increase quotas, deploy containers, create service accounts, or enable new AI services.
  • Build AI-specific incident response capabilities: Security teams should know how to quickly revoke AI credentials, shut down unauthorized workloads, preserve evidence, investigate cloud identities, and determine whether attackers accessed sensitive data.

How LLM Jacking Will Evolve

LLM jacking reflects a broader transformation in cybersecurity. As organizations invest more heavily in generative AI, AI agents, cloud GPUs, proprietary models, and AI-enabled applications, those resources will become increasingly attractive to attackers. The threat also intersects with other emerging risks, including cloud account takeovers, supply chain attacks, infostealers, API security breaches, identity attacks, and AI-enabled cybercrime.

The organizations best positioned to defend themselves will be those that stop treating AI as simply another software application and instead recognize it as a new enterprise attack surface requiring specialized security controls, monitoring, governance, and expertise.

How Cybersecurity Professionals Can Learn to Combat LLM Jacking

LLM jacking is only one example of the security challenges emerging as organizations rapidly adopt AI. Cybersecurity professionals increasingly need to understand AI attack surfaces, cloud infrastructure, adversarial AI techniques, AI governance, model security, and the ways attackers can exploit AI systems.

EC-Council University (ECCU) is preparing cybersecurity professionals for this evolving threat landscape through our flagship AI security certification courses:

Taken together, these courses help cybersecurity professionals build practical, forward-looking skills to secure AI systems and manage the risks associated with their adoption, such as LLM jacking. As attackers learn to exploit AI resources, organizations need professionals who understand how to defend them. Now is the time to build those skills.

To know more about our AI-focused cybersecurity courses:

Frequently Asked Questions

LLM jacking is the unauthorized use of stolen AI credentials, AI accounts, cloud infrastructure, computing resources, or AI services. Cybercriminals may use the stolen resources themselves or sell access to other threat actors.

Cryptojacking typically involves hijacking computing resources to mine cryptocurrency. LLM jacking similarly abuses someone else’s computing resources, but attackers use them to access or operate AI models, AI applications, GPUs, or other AI workloads.

AI services and high-performance computing resources can be expensive. Stolen access allows criminals to obtain AI capabilities without paying the full cost and can also provide resources for other cybercriminal activities.

Attackers can steal AI credentials through phishing, infostealer malware, exposed API keys, compromised developer environments, compromised cloud accounts, and improperly secured configuration files.

Yes. If attackers gain sufficient permissions, they can create or scale computing resources and generate unauthorized AI or cloud consumption. Organizations should monitor cloud spending and resource utilization for unexpected activity.

Yes. A compromised AI or cloud environment may expose credentials, prompts, datasets, source code, proprietary research, model configurations, or other sensitive information, depending on the attacker’s permissions.

Organizations should protect API keys and secrets, enforce least privilege, secure developer environments, implement strong identity controls, restrict cloud provisioning, monitor AI and cloud activity, establish spending alerts, and maintain AI-specific incident-response procedures.

LLM jacking demonstrates how AI, cloud security, identity, application security, and cybercrime are converging. Professionals who understand these overlapping attack surfaces can help organizations securely adopt AI while reducing financial, operational, and data-security risks.

Share this post

Recent Posts

INQUIRE NOW

Related Posts

Are you looking to pursue a career in cybersecurity?

Unlock Your Cyber Security Potential at EC-Council University

Admission Inquiry

Admission Inquiry