LLMjacking can run up your business’ AI bill fast – how to stop it

Security experts are warning of a growing underground market for stolen AI account credentials, a practice known as LLMjacking. John Hultquist, chief analyst for the Google Threat Intelligence Group, told the Financial Times that the cybersecurity unit has seen a "major increase" in LLMjacking over 2026.
LLMjacking is described as the AI equivalent of cryptojacking: using AI power and resources that do not belong to the user. Cybercriminals seek credentials or API keys that grant access to business AI accounts, which often carry high or unlimited usage limits, with token overspill charged outside typical subscription costs.
Credentials and API keys can be obtained through corporate network access, phishing, data breaches, vulnerabilities or insider threats. According to the report, criminals use the access for high-level computing tasks requiring tokens, running their own malicious AI models or tasks, extracting sensitive corporate information fed into a victim's model, or poisoning training datasets. Stolen credentials and API keys can also be resold to other cybercriminal groups.
Sysdig's Threat Research Team estimates unauthorized use can cost around $46,000 and even over $100,000 per day on top-tier models. Hultquist said the team has spotted illicit access to models from Anthropic, Google and OpenAI offered at up to 97% off, with some traders guaranteeing ongoing access if a compromised account is revoked or closed. He added that cybercriminals gain an "economic advantage" by using AI resources paid for by others while defenders face rising token costs.
Suggested defenses include training and awareness programs, frequent audits of misconfigured instances and exposed data, regular patch cycles, least-privilege or zero-trust access frameworks, and avoiding hardcoded credentials and API keys. Businesses that suspect a breach should rotate all credentials and keys without delay, and if unusual AI usage such as activity spikes is found, consider temporarily revoking access and contacting their provider.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
Google analysts warn that stolen AI credentials are being sold underground, and businesses are footing the bill.