Back
Google Threat Intelligence Group finds AI model access sold on dark web marketplaces at up to 97% discounts
SiTech AI Team2 წთ. საკითხავი

Google Threat Intelligence Group finds AI model access sold on dark web marketplaces at up to 97% discounts

Researchers at the Google Threat Intelligence Group have recorded a surge in LLM-jacking: stolen AI logins and hijacked cloud servers are resold underground, and access to models from Anthropic, Google and OpenAI sells at discounts of up to 97%.

The Google Threat Intelligence Group (GTIG) has recorded a sharp rise this year in attacks that steal access to artificial intelligence systems, the Financial Times reported. The practice, known as LLM-jacking, covers both the sale of stolen login credentials for public AI tools and the theft of computing resources by groups that want to run their own models for free.

"What we are seeing in the underground is a growing economy associated with access to AI," John Hultquist, chief analyst at GTIG, told the FT.

Model access at a 97% discount

Dark web marketplaces are selling access to AI models from Anthropic, Google and OpenAI at discounts of up to 97%, according to the report. For comparison, subscriptions to the most advanced versions of ChatGPT and Claude can cost as much as $200 per user per month.

Some sellers also offer what they call "guaranteed access": if an account is blocked, the buyer receives replacement credentials at no extra cost, Hultquist said.

Servers hijacked to run someone else's models

Beyond stolen accounts, the report describes criminal and state-backed groups breaking into companies' cloud-hosted servers and loading their own AI models onto the compromised systems. The method echoes earlier attacks in which intruders used victims' machines to mine cryptocurrency.

One such incident involved a "very active" Chinese cyber espionage group that has previously targeted the United States, according to the FT.

An economic edge for attackers

Hultquist warned that cheap AI access gives attackers an economic and efficiency advantage over defenders, who must pay full price for the same tools. In his view, the best moment for intruders to hide is now, while companies are still learning how much AI they will use.

"You might think a sudden major increase in compute usage is completely normal because you have just adopted all this AI infrastructure. It's a real opportunity for somebody to hide in the noise," he said. "Anybody who decides that AI is a fad and wants to let it just wash over them is going to wake up one day underwater."

The warning follows Anthropic's most recent quarterly misuse-of-AI report, which identified threat actors trying to use its Claude tool for malicious activity in more than two dozen countries, including the US, UK and Yemen.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.