LLM-jacking is an emerging cybersecurity threat in which criminals steal cloud credentials or artificial intelligence (AI) API keys to run expensive computing workloads without permission. The attack can leave businesses, developers and other cloud users facing unexpected bills, compromised data and serious security risks.
Artificial intelligence has transformed how businesses develop software, automate tasks and process information. However, the computing resources behind these technologies have also created new opportunities for cybercriminals. As organizations increasingly rely on cloud platforms and AI services, attackers are finding ways to exploit poorly protected accounts and use other people’s computing resources for their own activities.
One growing concern is LLM-jacking, a form of cybercrime that allows attackers to access large language models (LLMs) and other AI computing services using stolen credentials. Rather than investing in expensive hardware or paying for cloud subscriptions, criminals exploit legitimate accounts to obtain computing power at someone else’s expense. The account holder may remain unaware until unusual activity appears or a substantial invoice arrives.
The threat highlights a wider challenge in the expanding AI economy. Cloud computing makes powerful technology accessible to businesses of different sizes, but it also means that a single exposed credential can potentially provide access to valuable infrastructure. Developers who publish code online, companies that manage multiple cloud environments and startups experimenting with AI services may all face risks if their security controls are inadequate.
LLM-jacking can also extend beyond unauthorized computing. Depending on the permissions attached to a compromised account, attackers may access sensitive information, misuse AI tools, change cloud settings or establish access to additional systems. Consequently, understanding how this attack works and recognizing its warning signs are important steps toward protecting digital infrastructure.
What Is LLM-Jacking and Why Is It a Growing Concern?
LLM-jacking describes the unauthorized use of another person’s or organization’s AI computing resources, typically through stolen cloud credentials, access tokens or API keys.
The term draws a comparison with cryptojacking, a cybercrime technique in which attackers secretly use compromised computers or servers to mine cryptocurrency. The central idea is similar: criminals shift the cost of computing onto someone else while keeping the benefits for themselves.
However, LLM-jacking targets the resources needed to operate AI models and related services. These resources may include graphics processing units (GPUs), cloud-hosted virtual machines, model inference services and specialized AI application programming interfaces.
Running large AI workloads can consume substantial computing capacity. Depending on the service, model and volume of requests, usage charges can accumulate quickly. For an attacker, gaining access to an account with generous computing limits can therefore provide a valuable resource without the expense of establishing an independent infrastructure.
Google has highlighted this threat through its cloud security investigations, including work by its Mandiant threat intelligence team. Reported incidents involving exposed credentials illustrate how attackers can turn legitimate cloud access into unauthorized AI infrastructure.
The wider concern is that LLM-jacking exploits trusted services rather than necessarily requiring criminals to break through every layer of a cloud provider’s defenses. If valid credentials are exposed, attackers may be able to operate through ordinary account functions until monitoring systems identify suspicious behavior.
How LLM-Jacking Attacks Work
Understanding the typical attack process helps organizations identify weaknesses before they lead to financial losses or data exposure.
1. Attackers Obtain Cloud Credentials
Many LLM-jacking incidents begin with compromised authentication information. This may include an API key accidentally published in a code repository, a personal access token exposed through a development project or a session credential stolen by malware.
Developers sometimes place credentials directly in application code or configuration files. If these files become publicly accessible, an attacker may discover the secrets through automated scanning or targeted research.
Credentials can also be exposed through compromised developer accounts, insecure storage systems or inadequate access controls. The precise method depends on the victim’s environment and the attacker’s capabilities.
2. Criminals Access the Victim’s Cloud Account
Once attackers obtain usable credentials, they attempt to access the associated cloud account or AI service.
The level of access depends on the permissions assigned to the compromised credential. Some credentials may allow only limited API requests, while others could permit the creation of computing resources, modification of settings or access to sensitive data.
This distinction matters because excessive permissions can turn a relatively small security lapse into a much broader incident.
3. Unauthorized AI Workloads Begin Running
After gaining access, attackers may create virtual machines, launch AI workloads or send requests to paid model APIs.
They can use the resources to run AI models, automate coding tasks, conduct large-scale data processing or support other online operations. Some may also attempt to resell access to compromised accounts or use the infrastructure to operate automated agents.
Because the activity takes place within a legitimate cloud environment, it may initially resemble normal customer usage. Unusual computing demand, unfamiliar access locations and unexpected service configurations can provide important clues.
4. The Account Owner Discovers the Abuse
Victims may discover LLM-jacking through unexpected cloud bills, sudden increases in API consumption or alerts about resource usage.
In other cases, the first warning may be a service interruption, a disabled account or evidence that confidential information has been accessed without authorization.
The time between the initial compromise and its discovery can affect the extent of the damage. If attackers remain undetected, unauthorized workloads may continue consuming resources and generating charges.
Why Hackers Target AI Cloud Infrastructure
The financial value of AI computing is a major reason criminals target cloud accounts. Access to GPUs and paid AI services can be expensive, particularly when workloads involve large models or sustained processing demands.
By using stolen credentials, attackers shift those costs to the account holder. This arrangement can support several types of unauthorized activity.
Reducing the Cost of AI Operations
Criminals can use compromised accounts to run models without paying the legitimate service fees. Depending on the available permissions and computing limits, they may access resources that would otherwise require a substantial investment.
This can make stolen infrastructure attractive to individuals or groups seeking computing capacity without maintaining their own systems.
Supporting Automated Cybercrime
AI services can assist with tasks such as processing information, generating text and automating software-related workflows. In the hands of malicious actors, these capabilities may support phishing operations, credential theft attempts or automated vulnerability research.
However, access to an AI model does not automatically give an attacker the ability to compromise other systems. The potential impact depends on the tools available, the attacker’s objectives and the security measures protecting the target.
Reselling Unauthorized Access
Some attackers may attempt to monetize compromised cloud accounts by offering access to computing resources or AI services to other users.
This creates an additional risk because multiple parties may use the same compromised infrastructure, making suspicious activity harder for the account owner to interpret.
Accessing Sensitive Information
A compromised cloud account may expose proprietary prompts, model configurations, source code, datasets or other confidential information.
The extent of possible exposure depends on the permissions attached to the stolen credentials and the architecture of the affected environment. Accounts with broad administrative access can create a wider security risk than accounts restricted to a single task.
The Financial and Security Risks of LLM-Jacking
Unexpected computing charges are among the most visible consequences of LLM-jacking. Yet the financial impact represents only one part of the problem.
Unauthorized workloads may consume resources needed by legitimate applications, slowing services or affecting business operations. If cloud spending rises sharply, an organization may also encounter budget overruns or service restrictions.
Data exposure presents another concern. Attackers who obtain sufficient permissions may access information stored in cloud environments or use compromised infrastructure as an entry point for further activity.
In more extensive incidents, criminals may attempt to move between connected systems, alter account permissions or compromise additional credentials. Such actions can increase the scope of an investigation and make recovery more complicated.
Small businesses and startups may face particular operational difficulties when an unexpected bill competes with normal spending requirements. Nevertheless, organizations of every size should assess their exposure according to their cloud usage, account privileges and security controls rather than assuming that their size determines their risk.
How Google Cloud and Other Providers Can Detect Suspicious Activity
Cloud providers use security monitoring and account controls to identify potentially unauthorized behavior. Google has described monitoring for unusual virtual machine creation, abnormal resource consumption, suspicious API activity and access patterns that differ from expected behavior.
These signals can help identify activity that does not match an account’s established usage. For example, a sudden increase in GPU consumption or the creation of unfamiliar computing resources may warrant investigation.
Depending on the provider, the service and the circumstances, security systems may restrict suspicious traffic, flag an incident or isolate affected resources.
However, automated detection is not a guarantee that every attack will be stopped immediately. Attackers may operate through valid credentials, and legitimate workloads can sometimes resemble suspicious activity.
For that reason, organizations should combine provider-side monitoring with their own access controls, billing alerts and regular reviews of account activity.
The same principles apply across Google Cloud, Amazon Web Services (AWS), Microsoft Azure and paid AI API platforms. The specific tools differ, but the underlying objective remains the same: detect unauthorized usage early and limit the damage a compromised credential can cause.
How to Protect Your Cloud Account From LLM-Jacking
Preventing LLM-jacking requires consistent credential management, restricted permissions and active monitoring. The following measures can help reduce exposure.
Keep API Keys and Tokens Out of Public Repositories
Never place secret credentials directly in publicly accessible source code, documentation or configuration files.
Use approved secret-management tools and protected environment variables to store sensitive information. Developers should also enable repository secret scanning where available.
If a key or token becomes exposed, treat it as compromised. Revoke or rotate it promptly, investigate potential use and check whether related credentials may also have been affected.
Removing a secret from a repository alone is insufficient because copies may remain in commit history, cached data or third-party archives.
Apply the Principle of Least Privilege
Give each user, application and service account only the permissions required to perform its assigned tasks.
For example, an application that only needs to send requests to a particular AI service should not automatically receive broad administrative access to the entire cloud environment.
Separate credentials by application and workload wherever practical. This approach limits the number of systems an attacker could affect if one credential is compromised.
Enable Multifactor Authentication
Multifactor authentication (MFA) adds another verification step to supported sign-in processes. It can reduce the risk associated with stolen passwords, particularly for administrators and other privileged users.
Organizations should also use short-lived credentials and workload identity mechanisms where supported. These controls can reduce reliance on long-lived secrets that remain valid for extended periods.
MFA does not replace API key security, so non-interactive credentials still require appropriate protection and rotation.
Set Billing Budgets and Usage Alerts
Configure spending budgets, billing notifications and usage alerts for cloud projects and AI services.
Set GPU quotas and API consumption limits according to legitimate business needs. Where possible, establish alerts for unusual spending increases or unexpected demand.
These measures may not prevent every unauthorized request, but they can help teams identify unexpected consumption before costs grow further.
Review Audit Logs Regularly
Cloud audit logs can reveal changes to permissions, newly created virtual machines, unfamiliar access locations and unexpected API calls.
Security teams should investigate activity that differs from normal operating patterns, especially when it coincides with increased computing usage or new account permissions.
Centralized logging and automated alerts can make suspicious behavior easier to identify across multiple projects.
Separate Development, Testing and Production
Keep development, testing and production environments separate wherever practical. Use distinct accounts or projects, different credentials and appropriate network restrictions.
This separation helps prevent a compromised development token from automatically granting access to production systems or sensitive customer information.
Organizations should also review who can create expensive computing resources and establish approval controls for workloads that could significantly increase spending.
Who Faces the Greatest Exposure to LLM-Jacking?
LLM-jacking primarily concerns people and organizations that manage cloud infrastructure, paid AI services or credentials that permit access to billable computing resources.
Developers may be exposed when they handle API keys or publish code. Startups can face risks when multiple team members share broad permissions or deploy experimental applications without adequate monitoring.
Larger enterprises may operate complex cloud environments with many service accounts, projects and integrations. This complexity can make credential management and unusual-activity detection more challenging.
AI researchers and organizations training or hosting models should also examine how they protect datasets, model configurations and computing resources.
Consumers who use ordinary AI applications face a different set of risks. Their main concerns generally involve account compromise, privacy and unauthorized access to personal information rather than direct misuse of a GPU cluster billed to them. However, anyone using a paid AI API or cloud development platform should understand how their account credentials and usage charges are managed.
As AI adoption expands, cloud security practices will remain important for organizations seeking to use these services without exposing their budgets, infrastructure or sensitive information to unauthorized access.






