# Hackers hijack AI accounts and servers to fuel a booming cyber crime economy

> Source: <https://cryptobriefing.com/hackers-hijack-ai-accounts-cyber-crime/>
> Published: 2026-09-26 10:38:35+00:00

# Hackers hijack AI accounts and servers to fuel a booming cyber crime economy

Stolen API keys and session tokens for major AI platforms are being resold on dark markets at steep discounts, costing companies millions in unauthorized compute charges

There’s a new kind of heist happening, and nobody needs a ski mask. Hackers are stealing login credentials and API keys for major AI platforms, then burning through someone else’s compute budget at industrial scale. One documented incident saw nearly 200,000 API requests fired through a single compromised corporate account in just two minutes.

The practice has a name now: LLMjacking. Think of it as carjacking, but instead of a vehicle, the target is access to large language models from providers like [OpenAI](https://cryptobriefing.com/markets/openai/), [Anthropic](https://cryptobriefing.com/markets/anthropic/), and [Google](https://cryptobriefing.com/markets/alphabet/). The stolen goods get flipped on underground marketplaces, typically at 40% to 60% discounts off retail pricing.

## How the pipeline works

The attack chain starts with infostealer malware, a category of lightweight tools designed to quietly siphon browser-stored passwords, API keys, and session tokens from infected machines. Once attackers have valid credentials for a corporate AI account, they can access the same compute resources the legitimate owner is paying for.

CrowdStrike’s 2026 Threat Hunting Report documents an 89% increase in AI-related adversary activities between July 2025 and June 2026. That figure captures everything from credential theft to full-blown infrastructure compromise.

Average prices for stolen AI accounts have more than doubled in 2026, according to Google Threat Intelligence.

### AI, tech, and the markets they move—in one daily briefing.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

## The scale is staggering

Okta’s security team analyzed a 7 GB dump of infostealer logs from September 2026 and found hundreds of unexpired tokens tied to AI services.

In that same month, autonomous AI-agent campaigns compromised infrastructure across 395 organizations in 48 countries. The attacks often mimic legitimate usage patterns, which is what makes them so difficult to detect.

Stolen access to over 30 different LLM providers was being resold on underground markets in 2026.

## Why detection is so difficult

The core challenge for defenders is that stolen credentials produce activity that looks legitimate at the protocol level. An API key doesn’t know who’s holding it. If the request format is correct and the authentication token is valid, the platform processes it.

Traditional anomaly detection can catch volume spikes, like the 200,000-request burst mentioned earlier. But more sophisticated attackers throttle their usage to stay under monitoring thresholds, spreading activity across multiple stolen accounts to keep any single one from triggering alerts.

**Disclosure:** This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
