Stolen AI access fuels a growing underground cybercrime market

0
74
Cybercriminals turn stolen AI access into a growing underground market
Cybercriminals turn stolen AI access into a growing underground market

As AI adoption expands, cybercriminals are increasingly turning AI systems themselves into targets, stealing access to accounts and computing infrastructure to use powerful models without paying their full costs.

Security researchers say the practice, known as “LLM-jacking”, is developing into an underground business. Google Threat Intelligence Group has reported a sharp rise in such activity this year, with attacks ranging from stolen credentials for AI services to compromised corporate servers used to run AI models.

The stolen resources can then support cybercrime, espionage and other malicious activities.

Access to advanced AI models can be expensive. Premium subscriptions to services such as ChatGPT and Claude can cost up to USD200 per user each month, while running large models independently requires significant computing infrastructure.

Researchers have identified dark web marketplaces offering unauthorised access to models from OpenAI, Anthropic and Google at discounts of up to 97%. Some sellers reportedly offer replacement credentials when compromised accounts are blocked, as AI companies monitor accounts for suspicious activity.

John Hultquist, chief analyst at Google Threat Intelligence Group, said an underground economy was developing around AI access. The low cost of stolen access could give attackers a financial advantage over organisations defending against them.

Cybercriminals are also targeting AI computing power directly. Researchers have observed attacks in which hackers break into cloud servers and install their own AI models, allowing them to use another organisation’s processing capacity.

The approach resembles cryptojacking, where attackers secretly use computers and servers to mine cryptocurrency. Similar tactics have been observed with AI, including an incident involving an active Chinese cyber espionage group that has previously targeted the United States.

AI is also becoming part of the wider cybercrime toolkit. Anthropic said it identified threat actors attempting to misuse Claude in more than 20 countries, including the United States, United Kingdom and Yemen.

A major challenge is detecting stolen computing power. As businesses expand AI workloads, sudden increases in server activity may not immediately appear suspicious, allowing attackers to hide among legitimate usage.

With companies investing more in AI models, servers and cloud infrastructure, protecting the computing systems behind AI is becoming increasingly important.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.