According to a report by the UK's Financial Times on the 26th, illegally obtaining AI models and computing power has quickly become the most sought-after commodity in the cybercrime black market. Hackers hope to use expensive large models for ransomware, cyber warfare, and espionage.
"LLM Hijacking" Rises, with Discounts Up to 97%
John Hultquist, chief analyst of Google's threat intelligence team, revealed that so-called "LLM hijacking" activities have significantly increased this year, characterized by the sale of stolen login credentials for publicly available AI tools, as well as some groups stealing others' computing power to run their own models for free. With 20 years of experience in cybersecurity, he said: "We are seeing an economic system around AI usage growing rapidly in the underground market."
Hultquist warned that attackers can use AI at a low cost, which gives them an advantage in terms of cost — those being attacked also need to use these tools, "in the end, these practices give them some kind of economic or efficiency advantage when they fight against us, because they can obtain these tokens at a much lower price." The Google team found that AI model access from companies such as Anthropic, Google, and OpenAI is sold on the dark web with discounts as high as 97%. In contrast, the highest subscription for ChatGPT and Claude can cost up to $200 (about 1,346 Chinese yuan) per user per month. Some sellers even offer "guaranteed access" services, promising to provide new credentials for free if the initial account is banned.
Infiltrating Clouds to Implant Models, Companies' Own Computing Power Becomes a New Target
Some criminal groups and state-sponsored organizations infiltrate servers where enterprises host their data, then implant their own AI models to run on the victims' systems — a method similar to using third-party devices for mining cryptocurrency. Hultquist warned that more and more large companies want to deploy custom AI models on their own servers instead of renting cloud computing power, and systems running independently will become targets of attacks. They must be carefully protected: "If you need to pay for your own computing power, and the cost may be very high... this computing power will become an important potential resource in the eyes of threat actors."
He believes that companies are still figuring out how much AI they should use, and for hackers, this is currently the best time to quietly infiltrate accounts and servers — a sudden increase in computing power usage might be mistaken for normal activity, because "you just adopted these AI infrastructures, indeed, this is an opportunity hidden in the noise."

