ThreatCluster

LLMjacking Attack Exploits Leaked AWS IAM Key to Access AI Models

First seen 4 Sep 2026, 09:51 UTC CybersecuritynewsGbhackers 59

Article Content

Browse articles
ThreatCluster

A recent LLMjacking attack has been documented, where threat actors exploited a leaked AWS IAM access key with AdministratorAccess permissions to hijack access to premium AI models, specifically targeting Amazon Bedrock. Security researchers at FortiGuard Labs traced the incident back to a long-lived AWS Identity and Access Management (IAM) access key. This attack method allows attackers to generate new identities and run inference on costly generative AI services, creating a significant revenue stream for the attackers. The incident highlights the vulnerabilities associated with cloud credential management and the potential financial impact on organizations relying on these AI services. As of now, the attack method has been confirmed and is a growing concern in the cybersecurity landscape.

Key Points: • LLMjacking exploits leaked AWS IAM keys to access premium AI models. • The attack utilizes long-lived credentials with AdministratorAccess permissions. • FortiGuard Labs confirmed the incident, emphasizing the financial implications for organizations.

Ask AI about this cluster

Timeline

2026-09-03
LLMjacking attack documented
FortiGuard Labs reported on the exploitation of a leaked AWS IAM access key to hijack AI model access.
Cybersecuritynews
2026-09-04
Gbhackers report on LLMjacking
Gbhackers published details on the attack, focusing on its impact on Amazon Bedrock AI models.
Gbhackers