Illegally seizing AI models and computing power is rapidly climbing to the top of the underground market's "most wanted" list. Hackers plan to use these expensive large models for ransomware, cyber warfare, and espionage.
John Hultquist, chief analyst at Google's Threat Intelligence Group, revealed that this year they have observed a significant increase in attacks called "LLM hijacking": some sell stolen login credentials of public AI tools, while others directly steal computing power and run their own models for free. This veteran with 20 years of security experience said that an "economy centered around AI access" is growing rapidly in the underground market.
Three-Fold Discount on Premium Accounts, Free Replacement if Banned
Gaining cheap access to expensive AI allows attackers to outspend defenders on paper—after all, defenders also need to use the same tools to protect themselves. Hultquist pointed out: they actually obtained these tokens at much lower prices.
Google found that on the dark web, there are already stalls selling access to models from Anthropic, Google, and OpenAI, with discounts as high as 97%. The premium subscription for ChatGPT and Claude can cost up to $200 per month per person, but here it is being sold at a huge discount. Since AI labs monitor abuse signs, some sellers even offer "guaranteed access": if the initial account gets banned, they will provide a new set of credentials for free.
Another method is even harsher: criminal groups or even state-backed organizations directly attack servers hosted by companies in the cloud and install their own models to run on them. This is similar to how hackers once infiltrated third-party machines to mine cryptocurrency. Hultquist believes that AI has been used by "all threat actors," and it will eventually become an essential part of security systems.
New Targets: Building Your Own Computing Power, Sneaking in Through Noise
Anthropic's latest abuse report mentioned that actors from over 20 countries, including the U.S., the UK, and Yemen, tried to misuse Claude for malicious purposes. Hultquist warned: anyone who thinks AI is just a passing trend and waits for it to fade will wake up one day to be overwhelmed—security incidents, alerts, and attacks will only increase, "you need to get your side in order now."
Join Now