Threat Insight

LLMjacking Is a New Cyber Threat

Hijacking other organizations’ digital resources has been a relatively common form of cybercrime for years. The most common form of resource hijacking is to hack corporate environments and install crypto mining software.

  • Insight

With the advent of large AI companies selling access to LLM on a Software-as-a-Service model where the customer pays for their token usage, criminals are now instead increasingly beginning to hack organizations and steal credentials or API keys that allows them to use organizations’ LLM accounts, effectively passing the bill for their AI usage to the victims. [1]

Organized cybercrime groups steal access to multiple LLM accounts and resell this stolen access on dark web markets. One of the largest operations discovered so far by researchers, involved almost 33 000 IP-addresses with software built to distribute and resell API quota from AI subscriptions. [2] An LLMjacking attack of a newer AI model such as Claude Opus 3.0 can cost upwards of $100 000 per day. [3]

Assessment

As major LLM companies, such as OpenAI and Anthropic are raising prices for access to their AI models and increasingly moving to per token payment plans, credentials for LLM accounts have become highly sought after by cybercriminals. The fact that USA is now trying to prevent certain countries, such as China, from having access to their latest AI models will likely increase the risk of LLMjacking even more. This type of crime will likely become even more prevalent in the future.

Securing this type of access is therefore increasingly relevant in a similar fashion to securing privileged identities or API keys. This is true for regular users, shared AI platforms but also credentials exposed in developer environments (e.g. as part of configuration files or otherwise hardcoded).

References

[1] https://www.practical-devsecops.com/llm-jacking-explained/
[2] https://x.com/teamcymru_S2/status/2082810654688190545
[3] https://www.sysdig.com/learn-cloud-native/what-is-llmjacking

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights