Google warns of a dangerous surge in model hijacking

Written by

Picture of فريقنا

فريقنا

Communications Consultant

Google cybersecurity experts have warned of escalating attacks involving the hijacking of AI resources and large language models on corporate servers and cloud accounts. These operations allow hackers to leverage expensive computing capabilities at cheap prices on the dark web, imposing heavy financial burdens and intelligence risks on organizations.

The digital world is witnessing the rise of a hidden and dangerous economy based on hacking AI accounts and servers and saddling companies with exorbitant computing costs, in an advanced replication of the cryptojacking phenomenon.

Google’s warnings and the rise of the stolen AI economy

Cybersecurity researchers at Google have issued a stern warning regarding the growth of a covert and thriving digital economy entirely centered on stealing and hijacking access privileges to artificial intelligence systems and models. This dangerous phenomenon has become known in security circles as “large language model hijacking” or “LLM jacking.” These attacks enable cybercriminals and disruptive groups to exploit ultra-powerful cloud resources and advanced language models at a negligible cost compared to their true value, while passing the burdensome financial losses onto hacked companies and organizations.

A black market for unauthorized access on the dark web

In a revealing interview with the Financial Times, John Hultquist, chief analyst at Google’s Threat Intelligence Group, explained that cyberattacks targeting AI accounts and cloud computing infrastructure experienced an explosive surge during 2026. Hultquist noted that dark web markets are now offering unauthorized access to the latest models from OpenAI, Anthropic, and Google with staggering discounts reaching up to 97% off their official prices.

Advanced enterprise subscriptions for services like ChatGPT and Claude cost around $200 per month per user, making stolen credentials and compromised corporate accounts a hot and highly tempting commodity for buyers among cybercrime syndicates. In fact, some vendors in these black markets have evolved their business models to bypass AI companies’ efforts to disable compromised accounts, offering “guaranteed access” packages that promise free and immediate alternative credentials if the original account is banned. Commenting on this landscape, Hultquist stated: “What we are seeing today in the underground markets represents a real, fast-growing economy entirely centered around selling and trading AI access.”

From cryptojacking to enterprise cloud hijacking

The risks of this phenomenon are not limited to stealing login data for individuals and employees; they also extend to organized crime syndicates and state-backed hacking groups infiltrating the cloud servers of major corporations and enterprises. Hackers deploy and run their own AI models directly inside the compromised infrastructure, shifting the burden of massive computing bills and energy consumption entirely onto unsuspecting victims.

This tactic closely mirrors the previous wave of cryptojacking attacks, where attackers seized devices to mine cryptocurrencies. Google researchers have observed identical methods applied to AI workloads, including the monitoring of intensive activity by a known Chinese cyber espionage group that previously targeted vital institutions in the United States. Experts expect these risks to escalate at an accelerated pace as more companies move to host custom AI models on their own servers rather than relying on third-party providers, turning them into rich targets loaded with valuable computing capabilities that attackers seek to loot.

Cost gaps favoring attackers and monitoring difficulties

Hultquist warned that the economics of AI theft heavily favor attackers, stating: “Hackers can obtain this immense computing power at virtually no cost, while we and organizations must pay the full price to protect ourselves and defend our systems.” He added that the early stages of deploying AI technologies within organizations pose a highly critical vulnerability point, as IT departments tend to dismiss sudden, massive spikes in computing resource consumption as normal occurrences driven by new system requirements, when they are actually caused by covert exploitation from external hackers.

Global abuse reports and escalating risks

In the same context, the latest quarterly abuse report released by Anthropic highlighted the magnitude and global expansion of this problem, revealing that the company detected intensive attempts by cyber threat actors to exploit Claude model tools for hostile and malicious purposes in more than 24 countries worldwide. Hultquist concluded his warnings with a decisive and direct statement reflecting the reality of the current security landscape: “Every cyber threat actor in the world is using artificial intelligence and relying on it today.”

Frequently asked questions

Question: What is the concept of LLM hijacking or model jacking?
Answer: It is the infiltration of cloud servers and accounts and the exploitation of their computing resources to run AI models at the victims’ expense.

Question: What is the discount percentage on stolen AI accounts on the dark web?
Answer: Access accounts for advanced models are sold with massive discounts reaching up to 97% compared to corporate official prices.

Question: Why is it difficult for companies to detect these breaches early on?
Answer: Because tech teams often believe that spikes in computing consumption and bills stem from the requirements of training and using their new systems.

شارك هذا الموضوع:

شارك هذا الموضوع:

اترك رد

الفئات

المنشورات الأخيرة

Discover more from Buzzinga

Subscribe now to keep reading and get access to the full archive.

Continue reading