/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google Threat Intelligence Group finds dark web marketplaces selling access to AI models, including from Anthropic, Google, and OpenAI, at up to 97% discounts

Security researchers warn of surge in ‘LLM-jacking’ attacks targeting companies' costly AI resources

Financial Times Tom Wilson

Context & Ripple Effects

The trade in illicit model access builds on OpenAI credentials found in stealer logs in 2023, showing that attackers have treated generative-AI accounts as a monetizable asset rather than merely a target for data theft.

It also broadens the security stakes around model access: Google Threat Intelligence Group had already documented hackers using AI in zero-day exploitation, while the reported LLM-jacking activity targets the costly underlying resources companies pay to use.

First-order effects

  • Anthropic, Google, and OpenAI face immediate account-abuse and revenue-leakage exposure as access to their models is resold through dark-web marketplaces at steep discounts.
  • Companies funding AI workloads become targets for LLM-jacking, putting their model-access credentials, usage limits, and AI budgets directly at risk.

Second-order effects

  • AI providers will need to tighten authentication, usage monitoring, and abuse controls, increasing friction for legitimate customers whose access patterns resemble bulk or automated use.
  • The illicit market compounds the pricing pressure already created by buyers seeking cheaper model alternatives, because unauthorized access creates a zero-authorized-cost substitute without provider support or contractual safeguards.

Third-order effects

  • If LLM-jacking persists, frontier-model access is likely to be managed less like a simple software subscription and more like a high-value security entitlement, with controls becoming part of product differentiation.
  • The pattern links cybercrime economics to AI distribution: providers that can secure access while keeping legitimate deployment workable gain an advantage over rivals whose access can be more easily diverted.

The trend: AI model access is becoming a contested distribution layer, where cost pressure and cybercrime both push providers to treat usage credentials and compute allocation as security-critical assets.