LLMjacking can run up your business’ AI bill fast – how to stop it
Google analysts warn that stolen AI credentials are being sold underground, and businesses are footing the bill.
Cybersecurity experts caution that the growing illicit trade of using other businesses' AI models and computing resources, known as LLMjacking, could result in steep AI costs for enterprises. The Financial Times quoted John Hultquist, chief analyst for Google Threat Intelligence Group, who reported a significant surge in LLMjacking since 2026.
LLMjacking operates similarly to cryptojacking, but instead of mining cryptocurrency, cybercriminals exploit AI power and resources they do not own. To gain unauthorized access to AI accounts, criminals may steal credentials or API keys through various means such as phishing, data breaches, vulnerabilities, or insider threats. Once they have access, they can utilize AI models without paying for the required tokens, which can lead to inflated billing and expenses ranging from $46,000 to over $100,000 per day for enterprise companies.
Hultquist explained that illicit access to AI models from companies like OpenAI, Anthropic, and Google is available for as much as 97% off, with some traders even guaranteeing continued access even after accounts are closed. The financial impact of LLMjacking extends beyond individual victims, as cybercriminals can gain an "economic advantage" by leveraging stolen AI power.
To mitigate the risk of LLMjacking, businesses must prioritize employee training and awareness, regular audits, and implementing the principle of least privilege, which restricts access to only the resources necessary for their tasks. Additionally, hardcoding credentials and API keys should be avoided, and any signs of unusual AI usage should prompt immediate action, including revoking access and contacting the service provider.
Written by urgent.news from ZDNet's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.