Security Experts Warn LLMjacking Surge Is Driving Up Enterprise AI Bills
Security experts say a criminal market for stolen AI credentials, known as LLMjacking, expanded sharply in 2026, with enterprises facing potential daily bills above $100,000 and stolen model access sold at steep discounts.
LLMjacking is the AI equivalent of cryptojacking. While cryptojacking describes stealing computing power to illicitly mine cryptocurrency, LLMjacking involves using AI power and resources that do not belong to the user. In the cybercriminal world, that means obtaining credentials or API keys that give authorized access to business AI accounts, which often have high usage limits, or potentially none at all, with token overspill charged outside typical subscription costs.
Cybercriminals can obtain username and password combinations or API keys by gaining access to a corporate network, stealing them through phishing, data breaches, vulnerabilities, or insider threats. That access lets criminals use an AI model without paying for the tokens themselves, whether to perform high-level computing tasks requiring tokens, run their own malicious AI models or tasks, extract sensitive corporate information fed into a victim’s model, or poison training datasets and ruin output. Once stolen, credentials and API keys can also be sold on the underground market to other cybercriminal groups.
As AI models from organizations including OpenAI and Anthropic become more sophisticated, capable, and skilled, they require more computing power. More power means more tokens must be purchased, or a higher subscription level must be bought. For enterprise companies, inflated billing caused by unauthorized users can climb rapidly. Sysdig’s Threat Research Team estimated costs of around $46,000 and even more than $100,000 per day on top-tier models.
Hultquist said the security team has spotted illicit access to AI models offered by Anthropic, Google, and OpenAI for up to 97% off, and some traders even guarantee ongoing access if a compromised account is revoked or closed. The combination of powerful AI and exposed credentials that can be easily purchased online helps explain why LLMjacking is growing in popularity, he said.
The financial damage is not limited to the victims of LLMjacking. Hultquist said cybercriminals gain an “economic advantage” by using AI resources paid for by others, while defenders are constrained by rising token costs.
AI accounts are a hot commodity, and owners must reduce the risk of compromise. Phishing remains a leading cause of account theft, so businesses should implement training and awareness programs beyond an annual tick-box exercise. Misconfigured instances, settings, and exposed data can all lead to LLMjacking, and security teams should be given the time and capacity to run frequent audits, as well as regular patch cycles to fix unpatched vulnerabilities that could provide unauthorized network access.
Businesses should also adopt the principles of least privilege, or zero trust, so employees have access only to the resources they need for their work, and only when they need them. That can reduce the risk of admin-level accounts being exploited for malicious purposes. Companies should avoid hardcoded credentials and API keys, and those that believe there has been a security breach should rotate all credentials and keys without delay. If unusual AI usage, such as spikes in activity, is found, they should consider temporarily revoking access and contact their provider.