Google’s Threat Intelligence Group has found dark web marketplaces selling stolen access to large language models (LLMs) from companies including Google, OpenAI and Anthropic at discounts of up to 97%.
The growing illicit economy involves a form of cybercrime known as LLM-jacking. Attackers steal credentials and computing resources to run AI models without paying or to sell access to others.
The attacks often involve compromising companies’ cloud-hosted servers and taking control of their AI resources. Security researchers warn that this gives cybercriminals an economic advantage: they can use expensive AI tools for activities such as extortion and espionage while the legitimate owners pay the costs.