Printing PressAI
← Back to front page
Business & Enterprise AI

LLMjacking can run up your business’ AI bill fast – how to stop it

Original reporting by ZDNet

Image via ZDNet

LLMjacking refers to the unauthorized use of artificial intelligence (AI) computing power and resources, effectively stealing access to sophisticated AI models. This burgeoning threat has fueled a booming underground economy where cybercriminals exploit stolen credentials to hijack enterprise AI accounts, turning their computational costs into illicit profits. Security experts, notably Google Threat Intelligence Group, report a "major increase" in LLMjacking through 2026, solidifying its status as a popular and costly criminal trend.

The criminal advantage

Mimicking cryptojacking, LLMjacking involves threat actors acquiring API keys or account credentials—often via phishing, data breaches, or insider threats—to gain unauthorized access to high-usage business AI accounts. This allows them to perform expensive computing tasks, run their own malicious AI models, extract sensitive corporate data, or even poison training datasets, all without incurring costs. With advanced AI models demanding substantial power and high token fees, criminals can then sell "guaranteed" access to these compromised resources for steep discounts, sometimes up to 97% off. Meanwhile, victim organizations face potential daily bills soaring into the tens of thousands of dollars and the added risk of data exposure, granting criminals a significant economic advantage in their operations. Protecting these valuable AI accounts has become an urgent priority for businesses.

The emergence of LLMjacking signals a critical maturation of the cyber threat landscape, demonstrating that the immense computational power and data processing capabilities of large language models are now prime targets for exploitation. Beyond the immediate financial drain from inflated bills and compromised data, the practice undermines the integrity of AI deployments and business operations, posing significant risks of data exfiltration and malicious model poisoning.

Wider Systemic Impacts

This illicit trade in AI credentials carries significant ripple effects. It grants cybercriminals an unfair economic advantage, allowing them to conduct sophisticated attacks or build their own malicious AI at no cost, while legitimate enterprises grapple with rising token expenses. This dynamic threatens to erode trust in cloud-based AI services, potentially stifling adoption and innovation as organizations weigh utility against heightened security risks and the imperative to defend against this evolving threat.

Looking ahead, LLMjacking underscores the imperative for a proactive and adaptive cybersecurity posture tailored specifically for AI environments. The future will demand not only advanced authentication and least-privilege principles but also AI-driven anomaly detection and continuous security audits to protect these valuable resources. The fight against LLMjacking is more than just about preventing financial loss; it’s about securing the foundation upon which the next generation of AI innovation will be built, ensuring its responsible and safe advancement for all.

Frequently asked questions

What is LLMjacking in cybersecurity and how does it affect businesses?
LLMjacking is a cybercrime where unauthorized individuals exploit stolen credentials or API keys to illicitly use a victim's AI computing resources and models. Similar to cryptojacking, it involves stealing processing power, but specifically for AI. Businesses face significant financial losses from inflated bills due to unauthorized usage, potentially incurring tens of thousands of dollars daily. It also puts sensitive data at risk and can degrade AI model integrity.
How do cybercriminals perform LLMjacking and what are their primary motives?
Cybercriminals perform LLMjacking by stealing user credentials or API keys, often through phishing attacks, data breaches, exploiting vulnerabilities, or insider threats. Once access is gained, they use the victim's AI resources for various malicious purposes. Their primary motives include conducting high-level computing tasks, running their own harmful AI models, extracting sensitive corporate data, or poisoning training datasets to corrupt AI outputs.
What are effective strategies for businesses to prevent LLMjacking attacks?
To prevent LLMjacking, businesses should implement robust cybersecurity practices. Key strategies include comprehensive employee training on phishing awareness, regular security audits, and timely patching of vulnerabilities. Adopting a least privilege or zero-trust framework, which limits employee access to only necessary resources, is crucial. Additionally, avoiding hardcoded credentials, continuously monitoring for unusual AI usage patterns, and promptly rotating all credentials and API keys after any suspected breach are vital defensive measures.
Intro and outro generated by Printing Press AI from the source article above. Always consult the original reporting for verbatim quotes and primary sources.