A growing cybercrime trend, dubbed LLM-jacking, has been flagged by Google, where attackers steal cloud credentials or API keys to use the victim's paid computing power for running AI models and automated agents. This leaves the account owner to bear the cost. The trend is similar to the older scheme of cryptojacking, where criminals hijacked servers to mine cryptocurrency, but now the prize is the costly GPUs that AI workloads depend on.

The attack typically begins with a mistake, such as a personal access token accidentally committed to GitHub, a leaked API key, or a session token lifted by malware. Once the attacker has the credential, they log into the victim's cloud account, switch on GPU-heavy virtual machines and AI services, and start running their models, coding tools, or attack infrastructure. The owner usually finds out when the invoice arrives or through degraded services, stolen data, or a suspended account.

Google's Mandiant team investigated an incident where an attacker used an exposed personal access token to deploy unauthorized AI infrastructure and scale up high-performance computing, leaving the customer responsible for the costs. The attackers' goal is to get free compute, allowing them to run or fine-tune models without paying for GPUs, operate AI agents for phishing, credential theft, and vulnerability scanning, and resell access to hijacked AI accounts.

Stolen infrastructure also gives criminals access to proprietary prompts, models, source code, and training data. The compromised account becomes a foothold for lateral movement into other systems, data theft, and automated attacks on other organizations, posing a deeper risk than just surprise charges. Google watches for sudden VM creation, abnormal resource use, suspicious API activity, and unusual access contexts to detect and mitigate such attacks.

To prevent such attacks, users with billable accounts on Google Cloud, AWS, Azure, or an AI API are advised to follow basic hygiene practices consistently. This includes keeping keys and tokens out of public repositories, rotating them if they may have leaked, and preferring short-lived credentials with least-privilege permissions. Turning on MFA for administrator accounts and setting billing budgets, anomaly alerts, and GPU quota limits can also help.

Additionally, reviewing audit logs for new VMs, changed permissions, unfamiliar regions, and unexpected AI usage can narrow the window an attacker has. Keeping development, testing, and production in separate accounts limits how far a single stolen key can travel. Users who only use a consumer AI app face a different exposure, mainly account theft and prompt privacy, rather than someone quietly taking over a GPU cluster.

The cloud version of the problem falls on developers, startups, and enterprises, along with anyone holding API credentials tied to a bill. By taking preventive measures, these users can protect themselves from the financial and security risks associated with LLM-jacking. Google and other cloud providers are working to detect and mitigate such attacks, but user vigilance is crucial in preventing them.

Key points

  • Attackers use stolen cloud credentials to run AI models and leave account owners with hefty bills.
  • Compromised accounts can become a foothold for lateral movement into other systems and data theft.
  • Basic hygiene practices, such as keeping keys and tokens secure, can help prevent LLM-jacking attacks.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.