LLMjacking Threat: Stolen AI API Credentials Fuel Massive Unauthorised Usage and Costs
What Happened — Cybercriminals are increasingly hijacking enterprise AI accounts by stealing API keys or login credentials. The illicit use—dubbed “LLMjacking”—lets attackers run high‑cost AI models on victim subscriptions, driving daily bills into the tens or hundreds of thousands of dollars and exposing corporate data fed into the models.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous monitoring of privileged API credentials—a core control‑assurance scenario.
- Highlights gaps in credential lifecycle management that can be documented as evidence for audit readiness.
- Shows how a breach of access controls can translate directly into financial impact and data exposure, underscoring the importance of defensible audit trails.
Who Is Affected – Enterprises across technology, finance, healthcare, and any sector that integrates external AI services (e.g., OpenAI, Anthropic, Google).
Recommended Actions –
- Inventory all AI service accounts and API keys; enforce least‑privilege and rotation policies.
- Deploy continuous monitoring to detect anomalous token usage and enforce usage caps.
- Incorporate AI‑specific credential controls into your broader identity‑access governance program. Source: ZDNet
Technical Notes – Attack vectors include phishing, credential theft from breached networks, insider misuse, and exploitation of vulnerable applications that store API keys in code or configuration files. No specific CVE is cited; the threat is driven by credential compromise rather than a software flaw. Source: ZDNet