Stolen AI model accounts sell cheap on darknet, self-hosted compute named a target
Stolen model accounts have become a black-market service, and self-hosted AI is now flagged as a high-value target.
ImportanceMaterialEvidenceE3 inspectableWrite-upQuick
Darknet sellers are offering large-model accounts at as little as 3% of the official price, and enterprises' self-hosted AI compute has been named a new target.
According to the Financial Times on September 26, John Hultquist, chief analyst at Google's threat intelligence team, said "LLM hijacking" has risen sharply this year: darknet markets are selling access to models from Anthropic, Google and OpenAI at discounts of up to 97%, with some sellers promising free replacement credentials if an account is banned.
Attackers use this cheap access to expensive models for ransomware, cyberwar and espionage; defenders rely on the same tools, which widens the cost gap.
Hultquist warned that as more companies deploy custom models on their own servers, that self-paid compute is becoming a resource attackers covet and should be defended as a high-value target.