Hackers hijack AI accounts and servers to fuel a booming cyber crime economy

50 minutes ago 1



There’s a new kind of heist happening, and nobody needs a ski mask. Hackers are stealing login credentials and API keys for major AI platforms, then burning through someone else’s compute budget at industrial scale. One documented incident saw nearly 200,000 API requests fired through a single compromised corporate account in just two minutes. The practice has a name now: LLMjacking. Think of it as carjacking, but instead of a vehicle, the target is access to large language models from providers like OpenAI, Anthropic, and Google. The stolen goods get flipped on underground marketplaces, typically at 40% to 60% discounts off retail pricing. How the pipeline works The attack chain starts with infostealer malware, a category of lightweight tools designed to quietly siphon browser-stored passwords, API keys, and session tokens from infected machines. Once attackers have valid credentials for a corporate AI account, they can access the same compute resources the legitimate owner is paying for. CrowdStrike’s 2026 Threat Hunting Report documents an 89% increase in AI-related adversary activities between July 2025 and June 2026. That figure captures everything from credential theft to ful...

Read Entire Article