Know
What is LLMJacking?
LLMJacking occurs when attackers obtain credentials or tokens that provide access to hosted AI services and then use the victim’s account for model inference, automated workloads, reselling access, or other abuse. It resembles cloud resource hijacking and cryptojacking but targets valuable AI model access and associated compute or quota.
Why it matters
CrowdStrike’s 2026 Threat Hunting Report describes AI systems as both attacker tools and targets and cites an LLMJacking campaign that generated nearly 200,000 API requests in two minutes, illustrating how quickly stolen AI access can create financial and operational impact.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Google documents agent-enabled credential harvesting and AI resource theft
Google's September 8 report describes a Q2 2026 case in which attackers compromised a cloud resource and planned, built, and executed an agent-enabled credential-harvesting campaign in under six hours. It also documents theft of AI credentials and unauthorized use of victim cloud resources.
The timeline describes one observed case, not an industry average or a claim that all attacks are autonomous. The report is newly published; the described activity occurred earlier.
CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours
CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.
These measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.
Understand the mechanics
How it works
- 1
Steal cloud, developer, or AI service credentials.
- 2
Discover available models, quotas, and regions.
- 3
Use or resell the victim’s AI access.
- 4
Generate large request volumes or automate downstream malicious workflows.
- 5
Hide activity among legitimate developer or service-account usage.
Practice
What to watch for
- Sudden model usage spike
- Requests from unfamiliar regions or workloads
- New model families used without deployment change
- High API consumption by dormant credentials
- AI spend inconsistent with business activity
Perform
What to do
- 1
Revoke and rotate affected credentials immediately.
- 2
Block unauthorized workloads and regions where possible.
- 3
Review cloud and AI service logs for lateral access.
- 4
Determine whether credentials exposed other cloud resources.
- 5
Set usage and cost alerts before restoring access.
How to reduce the risk
- Short-lived credentials
- Secrets management
- Scoped AI permissions
- Usage quotas
- Anomaly detection
- Cost alerts
- Workload identity instead of embedded keys
Business impact
- Unexpected AI/cloud cost
- Service quota exhaustion
- Credential compromise
- Potential use of corporate resources for malicious operations
What different roles should do
Developer / Cloud
- Never embed long-lived AI API keys in code or public repositories
Security
- Monitor AI service usage as cloud security telemetry
Framework & standards context
- MITRE ATT&CK Valid Accounts
- NIST AI RMF
Source transparency
Authoritative sources
Last reviewed: 2026-09-02