Google warns of rising LLMjacking costs hitting businesses
Google Threat Intelligence reports a surge in LLMjacking—a cybercriminal trend where stolen AI credentials are sold or misused to drain enterprise budgets. The tactic exploits high-limit API keys or subscription plans, letting attackers run unauthorized tasks, steal data, or poison training sets without paying token costs. Sysdig estimates daily charges of $46,000 to over $100,000 for top-tier…
Key points
- Google reports **97% off** stolen AI model access sold on underground markets, targeting OpenAI, Anthropic, and Google APIs
- Unauthorized use could cost businesses **$46,000–$100,000 daily** in token overspill, per Sysdig’s estimates
- Defenses include least-privilege access, credential rotation after breaches, and phishing training for employees
Cybercriminals obtain credentials via phishing, breaches, or insider threats, then sell access or use it for malicious AI tasks. Google’s team notes this creates an economic advantage for attackers while raising costs for defenders. To mitigate risks, businesses are advised to enforce least-privilege access, audit configurations regularly, avoid hardcoded credentials, and monitor for unusual token usage spikes.
The story so far
2 episodes →- Google warns of rising LLMjacking costs hitting businessesthis story
LLMjacking can run up your business’ AI bill fast – how to stop it
zdnet.com · 28 September 2026
Loading the full article…
This text was published by zdnet.com and written by Charlie Osborne. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Policy & Regulation
All →- Microsoft Copilot users may have their edited photos reviewed by humans · 1 src
- Florida AG Uthmeier seeks emergency injunction to halt OpenAI model development · 10 src
- OpenAI and Anthropic investigate tens of thousands of AI agent incidents as researcher warns some could be crimes · 15 src
- Anthropic warns investors AI models could pose existential risks in IPO prospectus · 23 src
- NVIDIA launches Open Agent Safety Platform with OpenShell and Sentry to isolate AI agents in milliseconds · 23 src
Comments
via GitHub Discussions