Stolen AI credentials fuel underground black market, threatening enterprise budgets
Google's threat intelligence team has identified a sharp rise in LLMjacking incidents during 2026, where criminals steal API keys and account credentials to access business AI systems without payment. The theft occurs through phishing, data breaches, and insider threats, allowing attackers to either exploit computational resources directly or resell the credentials on darknet markets. Unauthorized access to high-capacity accounts can result in massive unexpected charges as usage limits are exceeded.
The mechanics of LLMjacking mirror established cybercrime patterns adapted for AI infrastructure. Threat actors exploit multiple attack vectors—including phishing campaigns, network breaches, and compromised employee accounts—to obtain valid credentials. Once obtained, these credentials grant unrestricted access to enterprise-grade AI systems, enabling attackers to run sophisticated computational tasks at no cost while legitimate account holders absorb the operational expenses.
The underground market for stolen credentials has become increasingly sophisticated, with vendors offering guarantees against account revocation and pricing stolen access at steep discounts compared to legitimate subscription rates. This secondary market creates a two-tier economy where cybercriminals gain cost advantages in deploying AI-powered attacks while organizations face mounting defensive expenses tied to token consumption and security measures.
LLMjacking poses multifaceted risks to the broader business ecosystem. Enterprises could face severe budget impacts from unexpected charges, potentially affecting competitiveness and operational planning. The phenomenon may also create asymmetric advantages in cybercriminal operations, as attackers leverage others' resources for malicious activities while security teams operate under cost constraints. Additionally, if compromised accounts are used to access proprietary training data or manipulate AI outputs, downstream impacts could affect customers relying on these systems for critical decisions.