AI SecurityIntermediateThreat2 validated evidence records

LLMJacking

Also known as: Stolen LLM access, AI service account abuse, Unauthorized model consumption

30 sec

Unauthorized use of another organization’s cloud or API credentials to consume paid large-language-model services, steal AI capacity, or support further malicious activity.

Know

What is LLMJacking?

LLMJacking occurs when attackers obtain credentials or tokens that provide access to hosted AI services and then use the victim’s account for model inference, automated workloads, reselling access, or other abuse. It resembles cloud resource hijacking and cryptojacking but targets valuable AI model access and associated compute or quota.

Why it matters

CrowdStrike’s 2026 Threat Hunting Report describes AI systems as both attacker tools and targets and cites an LLMJacking campaign that generated nearly 200,000 API requests in two minutes, illustrating how quickly stolen AI access can create financial and operational impact.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationResearch / emerging practice

Google documents agent-enabled credential harvesting and AI resource theft

2026-09-08Google Threat Intelligence Group / Mandiant

Google's September 8 report describes a Q2 2026 case in which attackers compromised a cloud resource and planned, built, and executed an agent-enabled credential-harvesting campaign in under six hours. It also documents theft of AI credentials and unauthorized use of victim cloud resources.

Why this is evidence

The timeline describes one observed case, not an industry average or a claim that all attacks are autonomous. The report is newly published; the described activity occurred earlier.

See the source — Google Threat Intelligence Group / Mandiant: GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
Technical ValidationMeasured outcome

CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours

2026-08-03CrowdStrike Counter Adversary OperationsCross-sector

CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.

Why this is evidence

These measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.

See the source — CrowdStrike: 2026 Threat Hunting Report

Understand the mechanics

How it works

  1. 1

    Steal cloud, developer, or AI service credentials.

  2. 2

    Discover available models, quotas, and regions.

  3. 3

    Use or resell the victim’s AI access.

  4. 4

    Generate large request volumes or automate downstream malicious workflows.

  5. 5

    Hide activity among legitimate developer or service-account usage.

Practice

What to watch for

  • Sudden model usage spike
  • Requests from unfamiliar regions or workloads
  • New model families used without deployment change
  • High API consumption by dormant credentials
  • AI spend inconsistent with business activity

Perform

What to do

  1. 1

    Revoke and rotate affected credentials immediately.

  2. 2

    Block unauthorized workloads and regions where possible.

  3. 3

    Review cloud and AI service logs for lateral access.

  4. 4

    Determine whether credentials exposed other cloud resources.

  5. 5

    Set usage and cost alerts before restoring access.

How to reduce the risk

  • Short-lived credentials
  • Secrets management
  • Scoped AI permissions
  • Usage quotas
  • Anomaly detection
  • Cost alerts
  • Workload identity instead of embedded keys

Business impact

  • Unexpected AI/cloud cost
  • Service quota exhaustion
  • Credential compromise
  • Potential use of corporate resources for malicious operations

What different roles should do

Developer / Cloud

  • Never embed long-lived AI API keys in code or public repositories

Security

  • Monitor AI service usage as cloud security telemetry

Framework & standards context

  • MITRE ATT&CK Valid Accounts
  • NIST AI RMF

Keep learning

API KeyCloud Credential TheftAI SecurityCryptojackingMachine Identity

Related entries are in the publication queue.

Source transparency

Authoritative sources

Last reviewed: 2026-09-02