INDEX 47 ▼1 todaySPLIT OF THE DAY OpenAI annual recurring revenue approaches $70 billion56 STORIES · 565 REACTIONSANTI-AI 74% · MIDDLE GROUND 16% · PRO-AI 9%LATEST AI researchers warn superintelligence extinction risk is around 50 percent
6 sources1 reaction

Google warns of surge in LLM-jacking attacks on AI accounts

20 DoomStory toneCyberattack warning, framed as escalating threat
6 sources · remio · NEWS.am TECH · Dataconomy
  • Doom: Stolen AI account credentials sold on dark web at up to 97% discount
  • Doom: Google issued a formal warning about a surge in LLM-jacking attacks
  • Doom: Targets include accounts from OpenAI, Google, and Anthropic
  • Doom: LLM-jacking lets attackers exploit AI services at victims' cost
The story in full

Google has issued a warning about a rising wave of cyberattacks called "LLM-jacking," in which hackers steal access credentials to AI services from providers including OpenAI, Google, and Anthropic. Stolen AI account access is being sold on the dark web at discounts of up to 97 percent off standard pricing, according to reporting across multiple outlets in late September 2026.

LLM-jacking refers to the unauthorized hijacking of legitimate AI account access, allowing attackers to use expensive AI services at the victim's expense. Google's warning signals that the practice has grown from isolated incidents into a broader pattern targeting major AI platforms.

Analysis

420 words

In late September 2026, Google issued a formal warning about a growing pattern of cyberattacks it labels LLM-jacking, in which criminals steal login credentials or API keys tied to AI service accounts at OpenAI, Google, and Anthropic. Once in possession of those credentials, attackers either use the accounts themselves to run costly AI queries or sell access on dark web markets at discounts reported to reach as much as 97 percent below standard retail pricing. The warning, surfacing across technology outlets between September 27 and 28, 2026, indicates the practice has moved beyond isolated opportunistic theft into something organized enough to sustain a secondary market.

The financial mechanics are what give this story weight beyond a routine credential-theft advisory. Premium AI API access is genuinely expensive at scale, and the victim of a hijacked account absorbs those costs without necessarily knowing their credentials have been compromised. A 97 percent discount on dark web markets implies attackers are pricing access low enough to attract bulk buyers while still profiting, which in turn suggests the supply of stolen credentials is substantial. The targets are not obscure platforms; OpenAI, Google, and Anthropic collectively host much of the enterprise and developer AI infrastructure in use today, so the exposure is broad. What remains genuinely disputed is how credentials are being obtained in the first place, whether through phishing, leaked API keys in public code repositories, or compromises of third-party tools.

The pro-AI camp has not yet published reactions to this story. Typically, that camp would be expected to argue that credential theft is a general cybersecurity problem that predates AI and reflects gaps in user security hygiene rather than flaws in AI platforms themselves. The anti-AI camp's response so far centers on the ubiquity of exposure: Golgariguy on Bluesky pointed out that most people already use Google and Microsoft services, framing LLM-jacking as an extension of existing risk onto systems people have little practical choice but to rely on. The middle ground camp has not yet commented, but would characteristically be expected to call for clearer credential monitoring tools from providers and stronger disclosure requirements when accounts are compromised.

The key things to watch are whether Google or the other named providers release specific figures on the scale of confirmed compromises, and whether any details emerge about the primary method attackers are using to harvest credentials. A concrete disclosure from OpenAI or Anthropic about account security incidents, or a follow-up technical report from Google's security teams, would either sharpen or soften the picture considerably.

Pro-AI
No Pro-AI voice has weighed in yet. Silence is a signal too.
Anti-AI1
Top quote
Like, we more or less all use Google services too, and many of us use Microsoft right?
Golgariguyvia Bluesky
Middle Ground
No Middle Ground take collected yet.

Add your take

0 reader votes

Sign in with Google to pick a side and post. Your vote moves the story's Doom / Boom score.

No more Pro-AI reactions
No more Anti-AI reactions
No more Middle Ground reactions
Pro-AI 0 · Anti-AI 1 · Middle Ground 00 reader takes

Sources

7 articles from 6 outlets
  1. remioGoogle LLM-Jacking Attacks Turn AI Access Into a Stolen Commodity
  2. NEWS.am TECHGoogle warns of a rise in 'LLM-jacking' cyberattacks
  3. DataconomyGoogle Warns Of Surge In AI Account Theft And LLM-jacking Attacks
  4. ChosunbizDark web sales of stolen AI accounts surge as LLM jacking spreads - CHOSUNBIZ
  5. ChosunbizDark web sales of stolen AI accounts surge as LLM jacking spreads - CHOSUNBIZ
  6. finance.biggo.comDark Web Sells AI Account Access at Up to 97% Discount; Google Warns of Surging "LLM-Jacking" Attacks
  7. NewsBytesHackers use 'LLM-jacking' to steal access from OpenAI Google Anthropic