Biz.Chosun Surge in Dark Web Sales of Stolen AI Accounts Amid LLM-Jacking Threat
Article Content
- •LLM-jacking has surged, with AI account access sold at up to 97% discounts on the dark web.
- •Cybercriminals are breaching enterprise cloud servers to deploy their own AI models, shifting costs to victims.
- •Organizations must enhance their defenses against AI-driven threats to avoid being overwhelmed by attacks.
Cybercriminals are increasingly targeting AI accounts and cloud computing resources, with illegal access to these models becoming a significant commodity on the dark web. John Hultquist from Google Threat Intelligence Group reported a rise in 'LLM-jacking,' where hackers steal and resell AI credentials at discounts of up to 97%. Major AI models from companies like Anthropic, Google, and OpenAI are being sold for just a few dollars, compared to their legitimate costs of up to $200 per month. Dark web sellers are also offering guarantees for replacement accounts if initial ones are banned. This trend has economic implications, as attackers can leverage expensive AI tools at a fraction of the cost, giving them an advantage over organizations that must pay full price for defensive measures. Hultquist emphasized that every threat actor is now utilizing AI, and organizations must enhance their defenses to counter this growing threat. The situation is evolving rapidly, with significant implications for cybersecurity strategies worldwide.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…