Press Enter to search · ESC to close

AI × Crypto

Hackers Target AI Accounts and Cloud Compute in ‘LLM-Jacking’ Crime Wave

Hackers are increasingly targeting AI accounts and cloud compute resources, selling access to premium models at up to 97% discounts and hijacking enterprise servers to run their own AI workloads. The trend poses new risks for cloud providers, AI firms, and cybersecurity stocks, while creating opportunities for defense-focused companies.

Hackers Target AI Accounts and Cloud Compute in ‘LLM-Jacking’ Crime Wave

A new form of cybercrime is rapidly scaling across the dark web, with hackers increasingly targeting expensive AI accounts and cloud computing resources. John Hultquist, chief analyst at Google Threat Intelligence Group, warned in a recent interview that attacks on AI accounts and compute resources have surged this year, giving rise to a technique dubbed “LLM-jacking.” Dark web markets are now selling access to premium AI models from Anthropic, Google, and OpenAI at discounts of up to 97%, while criminal gangs and state-backed hacking groups are breaching corporate cloud servers to run their own AI models at victims’ expense.

The Economics of AI Theft

The scale of this underground economy is striking. Top-tier subscriptions to services like ChatGPT and Claude can cost up to $200 per user per month. On the dark web, however, access credentials are being sold for a fraction of that price. Some sellers even offer “guaranteed access” — promising free replacement credentials if an account is banned — creating a stable, reliable black market supply chain.

Beyond account resale, a more direct attack vector is emerging: criminals are infiltrating enterprise cloud-hosted servers and deploying their own AI models directly on the compromised infrastructure. The victim pays the compute bill, while the attacker reaps the processing power. This mirrors the logic of cryptojacking, where hackers hijacked machines to mine cryptocurrency at the owner’s expense.

Market Implications: Cloud Providers and AI Firms Under Pressure

This trend carries significant implications for public markets. Cloud service providers — including Amazon Web Services, Microsoft Azure, and Google Cloud — could face rising security-related costs and potential liability concerns if enterprise customers demand stronger protections. The “cost asymmetry” Hultquist describes is a real threat: defenders pay full price for security, while attackers operate at a steep discount.

  • Cloud and AI stocks: Companies like Microsoft, Alphabet, and Amazon may see increased scrutiny over cloud security, potentially leading to higher R&D and compliance spending. While this is unlikely to dent revenues near-term, it could weigh on margins.
  • Cybersecurity sector: The rise of LLM-jacking is a tailwind for cybersecurity firms such as CrowdStrike, Palo Alto Networks, and Zscaler, as enterprises rush to bolster defenses around AI infrastructure.
  • AI model providers: Anthropic and OpenAI, though private, face reputational and operational risks. Publicly traded AI-adjacent firms could see volatility if abuse reports spook investors.
  • Crypto markets: The cryptojacking analogy is apt. If AI compute becomes the new “mined resource,” it could divert criminal attention away from crypto mining, potentially reducing illicit hash rate activity. However, it also underscores broader concerns about resource hijacking in decentralized compute networks.
  • Commodities and energy: AI compute is energy-intensive. If hijacked servers run at full capacity, they could distort local energy demand, though the macro impact remains limited.

The New Attack Surface: Internal AI Deployments

As more enterprises opt to build their own AI infrastructure rather than rent cloud capacity, internal systems become prime targets. Hultquist warns that the period immediately following AI infrastructure deployment is the most vulnerable. “You might think a sudden spike in compute usage is normal because you just brought a bunch of AI infrastructure online,” he said. “That gives attackers a real opportunity to hide in the noise.”

He added a stark warning: “Anyone who thinks AI is just a passing fad and wants to wait it out will one day find themselves drowning. They’ll face more incidents, more alerts, more attacks. We must organize our defenses now.”

Key Takeaways for Investors

  • Cybersecurity is a growth play: As AI adoption accelerates, so does the attack surface. Companies providing AI-specific security solutions are well-positioned.
  • Cloud providers face a double-edged sword: AI demand boosts revenue, but security breaches could erode trust and increase costs.
  • Watch for regulatory response: If LLM-jacking escalates, expect governments to tighten cybersecurity regulations for AI infrastructure, potentially raising compliance costs across the sector.
  • Crypto miners may face less competition: If criminals shift from cryptojacking to LLM-jacking, it could marginally reduce illicit mining activity, though the overall impact is likely small.

The convergence of AI and cybercrime is creating a new frontier of risk — one that investors in tech, cloud, and cybersecurity cannot afford to ignore.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback