
Someone is selling access to Claude, ChatGPT, and Google’s AI tools on darknet markets for as little as 3 cents on the dollar. That’s not a metaphor. According to researchers at Google’s Threat Intelligence Group, discounts of up to 97% on stolen AI accounts are now reported on underground marketplaces, and the people running these operations have thought of everything, including replacement credentials if a stolen account gets suspended.
John Hultquist, chief analyst at Google’s Threat Intelligence Group, told the Financial Times that attacks targeting AI accounts and cloud computing resources have risen sharply this year. The attack type getting the most attention has been dubbed “LLM-jacking,” and it’s spreading fast through cybercrime networks. Hultquist has 20 years in cybersecurity, and his read on this is direct: “Every threat actor is using AI.”
The underground market for stolen AI access
Premium AI subscriptions aren’t cheap. The top tier of Anthropic’s Claude costs up to $200 per user per month. So does ChatGPT’s highest plan. That price point makes stolen credentials genuinely valuable, and darknet sellers know it. They’ve built a gray-area industry around it, complete with service guarantees.
Some sellers are now offering “guaranteed access” packages. If the account gets flagged and suspended by the AI provider, the seller issues fresh credentials at no extra charge. That kind of after-sales support makes the illicit ecosystem more resilient to the detection efforts AI companies are actively running. It also tells you something about how organized this has become.
Anthropic’s latest quarterly misuse report found threat actors attempting to exploit its Claude tools in more than twenty countries, including the US, the UK, and Yemen. The uses aren’t just opportunistic. Hultquist says hackers are using AI access for ransomware attacks, cyber warfare, and espionage.
Hijacking cloud servers for free computing power
Account theft is only one side of this. The other approach is more aggressive and targets corporate infrastructure directly. Criminal groups and state-sponsored hackers are breaking into enterprise cloud servers and deploying their own AI models onto those systems, running their workloads on the victim’s hardware while the victim pays the bill.
The parallel to crypto mining is accurate and worth taking seriously. A decade ago, attackers compromised machines to mine Bitcoin on someone else’s electricity tab. The logic here is identical, just applied to GPU compute instead of CPU cycles. And AI inference is expensive enough that the incentive is at least as strong.
The cost problem defenders can’t ignore
Hultquist’s most pointed observation isn’t about the technical mechanics. It’s about economics. Attackers are getting AI capabilities at a fraction of market cost, while the organizations defending against them pay full price.
“These practices give them an economic or efficiency advantage,” he said, “because they can acquire that computing power at a much lower cost, while we have to pay full price to defend ourselves.” That asymmetry is a real problem, and it compounds over time.
There’s also a detection problem specific to AI infrastructure. When a company has just finished deploying a large AI system, a spike in compute usage looks normal. Attackers can hide inside that noise. Hultquist specifically called out the early deployment phase as the window where infiltration is hardest to spot.
What organizations need to watch for
The risk profile here is shifting fast. As more large enterprises move AI workloads onto private, in-house servers rather than renting from cloud providers, those internal systems become the new target. High compute costs mean high value to attackers.
For organizations thinking about what to monitor, the practical priorities are:
- Unusual spikes in cloud or on-premise GPU usage, especially in the weeks after new AI deployments
- Credential access patterns for AI service accounts, particularly outside normal working hours
- API call volumes to third-party AI providers that don’t match expected usage
- Any new or unrecognized model containers running on internal servers
Hultquist’s closing warning didn’t leave much room for interpretation. Organizations that treat AI security as someone else’s problem will face more incidents, more alerts, and more attacks. The time to act is before the breach, not after the compute bill arrives looking wrong.