sec.okta.com Exploitation of AI Service Accounts via Gray Market
Article Content
- •A gray market for AI service accounts is flourishing, particularly in China.
- •Fraudulent registrations exploit free trials and credits to gain access to AI models.
- •Okta emphasizes the need for better controls to manage fraudulent signups without hindering legitimate users.
A thriving gray market for AI service accounts has emerged, driven by high demand for discounted access to AI models, particularly in regions like China where access is restricted. Fraudulent registrations exploiting free trials and credits are a primary method of obtaining these accounts. Okta's Threat Intelligence team highlights that the illegal market is significantly larger in Chinese-language offerings compared to English-language ones. This situation poses challenges for legitimate service providers in controlling fraudulent signups while maintaining low friction for genuine users. The ongoing abuse of free and discounted AI services raises concerns about security and identity management across affected platforms. As of September 2025, companies like Anthropic have attempted to curb this trend by restricting access to unsupported regions, but the gray market continues to thrive.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (1)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Exploitation Confirmed Citrix has confirmed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in its NetScaler ADC and Gateway products, both scoring 9.5 on the CVSS scale. These vulnerabilities are actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary commands and potentially cause…