DigestAI news desk

Cut through the AI noise.

Policy & Regulation3 min read

Google warns of rising LLMjacking costs hitting businesses

Google Threat Intelligence reports a surge in LLMjacking—a cybercriminal trend where stolen AI credentials are sold or misused to drain enterprise budgets. The tactic exploits high-limit API keys or subscription plans, letting attackers run unauthorized tasks, steal data, or poison training sets without paying token costs. Sysdig estimates daily charges of $46,000 to over $100,000 for top-tier…

1 source

Key points

  • Google reports **97% off** stolen AI model access sold on underground markets, targeting OpenAI, Anthropic, and Google APIs
  • Unauthorized use could cost businesses **$46,000–$100,000 daily** in token overspill, per Sysdig’s estimates
  • Defenses include least-privilege access, credential rotation after breaches, and phishing training for employees

Cybercriminals obtain credentials via phishing, breaches, or insider threats, then sell access or use it for malicious AI tasks. Google’s team notes this creates an economic advantage for attackers while raising costs for defenders. To mitigate risks, businesses are advised to enforce least-privilege access, audit configurations regularly, avoid hardcoded credentials, and monitor for unusual token usage spikes.

The story so far

2 episodes →
  1. Google warns of rising LLMjacking costs hitting businessesthis story
Full story from zdnet.com · by Charlie Osborne · via Search: GoogleOpen source ↗

LLMjacking can run up your business’ AI bill fast – how to stop it

zdnet.com · 28 September 2026

Loading the full article…

This text was published by zdnet.com and written by Charlie Osborne. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗

Topics · follow one to build your own front page

The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.

Comments

via GitHub Discussions

More in Policy & Regulation

All →

Related stories