Cybercriminals Targeting AI Account Credentials to Exploit Corporate Computing Resources
Google threat intelligence analysts have identified a significant rise in LLMjacking incidents during 2026, where criminals steal AI credentials and API keys to access business AI systems without authorization. Threat actors obtain these credentials through phishing, data breaches, and network infiltration, then exploit them to run computationally expensive tasks or poison datasets while companies absorb the costs. Businesses are advised to implement account monitoring and access controls to prevent unauthorized use of their AI resources.
The underground market for compromised AI credentials has become a significant vector for corporate theft and fraud. Criminals employ multiple entry methods—phishing campaigns, exploiting network vulnerabilities, insider cooperation, and purchasing credentials from previous data breaches—to obtain the authentication tokens needed for unauthorized account access. Once acquired, these credentials enable attackers to exploit the substantial computational resources and generous usage limits typically associated with enterprise-tier AI services.
The economic incentive driving LLMjacking stems from the substantial operational costs of advanced AI systems. As models become more sophisticated, their token consumption increases proportionally, making legitimate usage expensive. By stealing credentials offering up to 97% discounts compared to standard pricing, threat actors dramatically reduce their operational expenses while simultaneously imposing massive unauthorized charges on victim organizations, potentially reaching six figures daily.
LLMjacking could significantly impact corporate cybersecurity budgets and operational resilience across industries relying on AI services. Organizations may face unexpected financial exposure from inflated usage bills, while simultaneously experiencing potential data theft and model poisoning that compromises business intelligence. The asymmetric advantage gained by well-resourced criminal groups using stolen AI compute may alter threat landscapes, particularly affecting smaller enterprises with limited security infrastructure and those unprepared for credential-based attacks targeting AI-specific infrastructure.