{"version":1,"type":"story","url":"https://digestai.news/story/google-warns-of-rising-llmjacking-costs-hitting-businesses","json":"https://digestai.news/story/google-warns-of-rising-llmjacking-costs-hitting-businesses.json","markdown":"https://digestai.news/story/google-warns-of-rising-llmjacking-costs-hitting-businesses.md","slug":"google-warns-of-rising-llmjacking-costs-hitting-businesses","headline":"Google warns of rising LLMjacking costs hitting businesses","summary":"Google Threat Intelligence reports a surge in LLMjacking—a cybercriminal trend where stolen AI credentials are sold or misused to drain enterprise budgets. The tactic exploits high-limit API keys or subscription plans, letting attackers run unauthorized tasks, steal data, or poison training sets without paying token costs. Sysdig estimates daily charges of **$46,000 to over $100,000** for top-tier models like those from OpenAI, Anthropic, and Google, with discounts up to **97% off** available on underground markets, according to John Hultquist, chief analyst at Google Threat Intelligence Group.\n\nCybercriminals obtain credentials via phishing, breaches, or insider threats, then sell access or use it for malicious AI tasks. Google’s team notes this creates an economic advantage for attackers while raising costs for defenders. To mitigate risks, businesses are advised to enforce least-privilege access, audit configurations regularly, avoid hardcoded credentials, and monitor for unusual token usage spikes.","keyPoints":["Google reports **97% off** stolen AI model access sold on underground markets, targeting OpenAI, Anthropic, and Google APIs","Unauthorized use could cost businesses **$46,000–$100,000 daily** in token overspill, per Sysdig’s estimates","Defenses include least-privilege access, credential rotation after breaches, and phishing training for employees"],"whyItMatters":"LLMjacking turns AI costs into a cybersecurity liability, forcing enterprises to balance security and spending while criminals exploit unpatched systems.","category":{"slug":"policy","name":"Policy & Regulation","url":"https://digestai.news/category/policy"},"entities":{"companies":["Google","OpenAI","Anthropic","Sysdig","Financial Times"],"models":[],"people":["John Hultquist"]},"firstPublishedAt":"2026-09-28T23:09:00Z","updatedAt":"2026-09-28T23:09:00Z","sourceCount":1,"hasPrimarySource":false,"sources":[{"outlet":"zdnet.com","title":"LLMjacking can run up your business’ AI bill fast – how to stop it","url":"https://zdnet.com/innovation/llmjacking-business-ai-bill-cost-how-to-stop","publishedAt":"2026-09-28T23:09:00Z","type":"press","primary":false,"lead":true}],"sourceNotes":null,"discussions":[],"thread":{"title":"Dark Web AI Model Theft Crisis","url":"https://digestai.news/thread/dark-web-markets-sell-access-to-anthropic-google-and-openai-models-at-97","storyCount":2},"cite":{"text":"Digest AI, \"Google warns of rising LLMjacking costs hitting businesses\", 28 September 2026, https://digestai.news/story/google-warns-of-rising-llmjacking-costs-hitting-businesses","publisher":"Digest AI","title":"Google warns of rising LLMjacking costs hitting businesses","datePublished":"2026-09-28T23:09:00Z","url":"https://digestai.news/story/google-warns-of-rising-llmjacking-costs-hitting-businesses"},"generatedBy":"Written by Digest AI's editorial model from the linked sources; the sources are the record.","license":"Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse"}