Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Plastic fused to coral rubble raises new concerns for ocean pollution

    September 30, 2026

    Sánchez Unveils Housing Reform Proposals After Eviction of 87-Year-Old

    September 29, 2026

    Don’t expect to look up and see a ‘2-moon night’ on Sept. 29, 2026

    September 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Plastic fused to coral rubble raises new concerns for ocean pollution
    • Sánchez Unveils Housing Reform Proposals After Eviction of 87-Year-Old
    • Don’t expect to look up and see a ‘2-moon night’ on Sept. 29, 2026
    • Hundreds detained as student protests across France turn violent | France
    • French hard-right leader Bardella accuses opponents of ‘total war’ after claims of antisemitism
    • From Brexit to electoral reform: key takeaways from Andy Burnham’s conference speech | Andy Burnham
    • LLMjacking can run up your business’ AI bill fast – how to stop it
    • OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    LLMjacking can run up your business’ AI bill fast – how to stop it

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 29, 2026 Technology No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ZDNET’s key takeaways

    • Security experts warn of a growing market in stolen AI account credentials.
    • LLMjacking, the illegal use of AI resources, is a popular criminal trend in 2026.
    • Businesses must monitor and protect their accounts. Here’s how.

    Security experts warn that it’s not just artificial intelligence (AI) going rogue that we have to worry about — there’s also a booming underground economy for selling access to your AI models and computing power. 

    Speaking to the Financial Times, John Hultquist, chief analyst for Google Threat Intelligence Group, said that the cybersecurity unit has seen a “major increase” in what is known as LLMjacking over 2026, a trend that could cost businesses dearly. 

    What is LLMjacking?

    If cryptojacking came to mind, you’re on the right track. While cryptojacking describes stealing computing power to illicitly mine cryptocurrency, LLMjacking is the AI equivalent: using AI power and resources that don’t belong to you.

    Also: OpenAI’s Dots: Like OpenClaw declawed – for $200/mo ChatGPT Pro users

    In the cybercriminal world, this means trying to secure credentials or API keys that give a criminal authorized access to business AI accounts, which often have high usage limits, or potentially none at all — with token overspill charged outside of typical subscription costs. 

    Cybercriminals can obtain username and password combinations or API keys by gaining access to a corporate network, stealing them via phishing, data breaches, vulnerabilities, or insider threats. This grants cybercriminals the opportunity to use an AI model without paying for the tokens themselves, for reasons such as:

    • Performing high-level computing tasks requiring tokens
    • Harnessing computing resources to run their own malicious AI models or tasks
    • Extracting and stealing sensitive corporate information fed into a victim’s model
    • Poisoning training datasets, ruining output

    Once stolen, credentials and API keys can also be sold on the underground to other cybercriminal groups. 

    The rising cost of LLMjacking 

    As AI models offered by organizations, including OpenAI and Anthropic, continue to advance in sophistication, capacity, and skill, they require more computing power. 

    The more power you need, the more tokens you need to purchase — or the higher the level of subscription you must purchase. 

    For enterprise companies, inflated billing caused by unauthorized users can climb rapidly, with Sysdig’s Threat Research Team estimating costs of around $46,000 and even over $100,000 per day on top-tier models.

    ‘Guaranteed’ access to dirt-cheap AI models

    Combine the raw power of AI and exposed credentials that can be easily purchased online, and you can see why LLMjacking is exploding in popularity. 

    Also: Who’s responsible for catching rogue AI agents? You are

    According to Hultquist, the security team has spotted illicit access to AI models offered by companies including Anthropic, Google, and OpenAI for up to 97% off, and some traders even guarantee ongoing access should a compromised account be revoked or closed. 

    The financial damage isn’t limited to the victims of LLMjacking. As the analyst points out, by leveraging stolen AI power, cybercriminals now gain an “economic advantage” in conducting attacks by using AI resources paid for by others, while defenders are constrained by rising token costs. 

    How businesses can defend themselves 

    AI accounts are a hot commodity, and it is up to owners to reduce the risk of compromise — especially with such high financial consequences at stake.

    Phishing is, and probably always will be, one of the main causes of account theft or exploitation, so implementing valuable training and awareness programs beyond an annual tick-box exercise is one of the first ways businesses can protect themselves.

    Also: Why phishing training doesn’t stop your employees from clicking scam links

    Misconfigured instances, settings, and exposed data can all lead to LLMjacking, and so security teams should be given the time and capacity to run frequent audits — as well as regular patch cycles to fix unpatched vulnerabilities that could provide unauthorized network access. 

    Another critical way to defend your organization against LLMjacking is to adopt the principles of least privilege. Least privilege, or zero trust, is a framework in which employees have access only to the resources they need for their work, and only when they need them, which can reduce the risk of admin-level accounts being exploited for malicious purposes.

    Finally, avoid hardcoded credentials and API keys, and businesses that believe there has been a security breach should rotate all credentials and keys without delay. If unusual AI usage, such as spikes in activity, is found, then consider temporarily revoking access and contact your provider.

    Charlie Osborne


    Contributing Writer


    Charlie Osborne is a cybersecurity journalist and photographer who writes for ZDNET and CNET from London. PGP Key: AF40821B

    See full bio

    bill business fast LLMjacking Run stop
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Anthropic Says It Discovered a Crispr-Like System. Now What?

    OpenAI’s latest features take direct aim at the app store model

    US ban on $1bn of Canadian goods takes effect in Trump’s latest retaliation | Business and Economy News

    Away’s New Series 3 Luggage Plays It Safe—That’s the Point

    OpenAI Gets Sued Over the Hugging Face Hack

    OpenAI takes on Microsoft with the launch of what feels a whole lot like ChatGPT’s own office suite

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Plastic fused to coral rubble raises new concerns for ocean pollution

    September 30, 2026

    Sánchez Unveils Housing Reform Proposals After Eviction of 87-Year-Old

    September 29, 2026

    Don’t expect to look up and see a ‘2-moon night’ on Sept. 29, 2026

    September 29, 2026

    Hundreds detained as student protests across France turn violent | France

    September 29, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Plastic fused to coral rubble raises new concerns for ocean pollution

    September 30, 2026

    Sánchez Unveils Housing Reform Proposals After Eviction of 87-Year-Old

    September 29, 2026

    Don’t expect to look up and see a ‘2-moon night’ on Sept. 29, 2026

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.