According to Google security researchers, who have recorded a sharp rise in so-called “LLM-jacking” attacks this year, a growing shadow economy built on trading stolen access to AI services is enabling cybercriminals to use powerful language models and cloud computing resources at prices far below legitimate rates.

Stolen AI on the dark web

John Hultquist, chief analyst at Google’s Threat Analysis Group, told the Financial Times that in 2026 there has been a sharp increase in hacking attacks targeting accounts and computing infrastructure tied to AI. Unauthorized access to OpenAI, Anthropic, and Google models is now being sold on dark web marketplaces at discounts of up to 97 percent. Premium subscriptions to services such as ChatGPT and Claude can cost as much as $200 per user per month, making stolen credentials an attractive commodity for criminal buyers.

Some sellers have adapted to AI companies’ efforts to block compromised accounts and now offer services with “guaranteed access,” promising free replacement credentials if the original account is blocked. “What we are seeing in the underground market is an emerging economy centered around access to AI,” Hultquist told the Financial Times.

From cryptojacking to AI-jacking

In addition to stealing accounts, criminal groups and state-backed hackers are breaching corporate cloud servers and deploying their own AI models on compromised infrastructure—effectively shifting enormous computing costs onto their victims. This method mirrors the earlier phenomenon of “cryptojacking,” in which attackers hijacked other people’s machines to mine cryptocurrency.

Google researchers have documented the use of similar schemes involving AI workloads, including by an active Chinese cyber-espionage group that had previously targeted the United States.

The threat is expected to grow as more companies move to host their own AI models on their own servers instead of using external cloud providers—thereby creating new attractive targets rich in the costly computing power that attackers seek.

Defenders face a cost gap

Hultquist warned that the economics of AI-enabled theft favor attackers. They can acquire computing power at a much lower price, while we have to pay full price for our own defense, he said. According to him, the early stages of enterprise AI adoption create a particular vulnerability: organizations may mistake spikes in computing resource consumption caused by attackers for normal workloads generated by their new systems.

Anthropic’s latest quarterly abuse report confirmed the scale of the problem: it found that malicious actors had attempted to use Claude tools for harmful purposes in more than two dozen countries. Hultquist was unequivocal: “Every threat actor is using AI.”