Skip to content
Tech News
← Back to articles

Google flags surge in 'LLMjacking' attacks stealing AI account credentials

read original get YubiKey 5 NFC Security Key → more articles
GoKawiil Brief

Google Threat Intelligence Group analyst John Hultquist told the Financial Times that his team has observed a major increase in LLMjacking throughout 2026. The technique involves criminals stealing API keys or login credentials to hijack businesses' AI accounts, exploiting high or unlimited usage limits to run up token costs or misuse compute resources without paying.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Because compromised AI accounts often carry generous usage allowances, victims could face unexpected bills or token overages that arrive as a surprise cost outside normal subscription pricing. The rise of a market for stolen credentials suggests cybercriminals see AI infrastructure as a lucrative new target, similar to how cryptojacking exploited stolen computing power, and experts frame this as a reason businesses should tighten credential monitoring now.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — Stolen credentials and API keys are exactly what fuel LLMjacking attacks, and hardware security keys like the YubiKey 5 NFC make phishing-resistant multi-factor authentication easy to enforce across your team. Adding a physical key to protect admin and cloud AI accounts is a concrete step toward locking down the access criminals are hunting for.”

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: zdnet.com — Charlie Osborne, 2026-09-29

Published there as: “LLMjacking can run up your business’ AI bill fast – how to stop it”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.