Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

LLMjacking Threat: Stolen AI API Credentials Fuel Massive Unauthorised Usage and Costs

Cybercriminals are hijacking enterprise AI accounts by stealing API keys, leading to unauthorised model runs that can cost organisations tens of thousands of dollars per day. The incident underscores the need for robust access‑control monitoring and audit‑ready evidence of credential stewardship.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 zdnet.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
1 recommended
📰
Source
zdnet.com

LLMjacking Threat: Stolen AI API Credentials Fuel Massive Unauthorised Usage and Costs

What Happened — Cybercriminals are increasingly hijacking enterprise AI accounts by stealing API keys or login credentials. The illicit use—dubbed “LLMjacking”—lets attackers run high‑cost AI models on victim subscriptions, driving daily bills into the tens or hundreds of thousands of dollars and exposing corporate data fed into the models.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous monitoring of privileged API credentials—a core control‑assurance scenario.
  • Highlights gaps in credential lifecycle management that can be documented as evidence for audit readiness.
  • Shows how a breach of access controls can translate directly into financial impact and data exposure, underscoring the importance of defensible audit trails.

Who Is Affected – Enterprises across technology, finance, healthcare, and any sector that integrates external AI services (e.g., OpenAI, Anthropic, Google).

Recommended Actions –

  • Inventory all AI service accounts and API keys; enforce least‑privilege and rotation policies.
  • Deploy continuous monitoring to detect anomalous token usage and enforce usage caps.
  • Incorporate AI‑specific credential controls into your broader identity‑access governance program. Source: ZDNet

Technical Notes – Attack vectors include phishing, credential theft from breached networks, insider misuse, and exploitation of vulnerable applications that store API keys in code or configuration files. No specific CVE is cited; the threat is driven by credential compromise rather than a software flaw. Source: ZDNet

📰 Original Source
https://www.zdnet.com/innovation/llmjacking-business-ai-bill-cost-how-to-stop/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →