A 97% discount sounds like a Black Friday deal. In this case, it’s stolen access to Claude, ChatGPT, and Gemini, sold openly on darknet marketplaces. According to Futunn News, John Hultquist, chief analyst at Google’s Threat Intelligence Group, told the Financial Times that attacks targeting AI accounts and cloud computing resources have risen sharply in 2024. And the attack pattern, now being called “LLM-jacking”, is maturing fast.
Hultquist has 20 years in cybersecurity. He isn’t someone who overstates things. So when he says every threat actor is using AI, that’s worth taking seriously.
What LLM-jacking actually looks like
There are two main vectors here. The first is account theft and resale. Stolen credentials for AI platforms from Anthropic, Google, and OpenAI are showing up on darknet markets at discounts of up to 97%. A top-tier Claude subscription or ChatGPT Plus plan can run $200 per user per month. At 97% off, attackers are getting access to frontier AI for almost nothing.
The second vector is more aggressive. Criminal groups, including state-sponsored ones, are breaking into corporate cloud servers and deploying their own AI models directly onto the victim’s infrastructure. They use the victim’s compute. They pay nothing. The victim foots the bill without knowing it. This is functionally identical to the old cryptojacking playbook, where hackers hijacked machines to mine Bitcoin. Same logic, different payload.
What makes the account resale market particularly durable is the customer service layer that’s built up around it. Some darknet sellers are now offering “guaranteed access” packages. If a stolen account gets suspended by the AI provider, the seller issues new credentials at no extra charge. That’s a real support model, and it makes the underground ecosystem more resilient against platform-level abuse detection.
The cost asymmetry problem
The most important point Hultquist makes isn’t technical. It’s economic. Attackers are acquiring AI compute at a fraction of market rate, while the organizations defending against them pay full price. That gap compounds over time. Defenders need to monitor more, respond faster, and absorb more incidents, all at full cost. Attackers need to spend almost nothing to run sophisticated AI-assisted operations.
Anthropic’s latest quarterly misuse report adds weight to this. Threat actors have been caught attempting to exploit Claude for malicious activity across more than 20 countries, including the US, UK, and Yemen. The range of use cases likely includes reconnaissance, phishing content generation, and support for ransomware and espionage campaigns.
Enterprise AI deployments are a new attack surface
There’s a specific risk window that Hultquist flags for enterprises moving away from cloud AI services toward self-hosted models. When a company deploys a large internal AI infrastructure, compute usage naturally spikes. Attackers know this. A sudden surge in resource consumption looks normal right after a deployment, which gives malicious actors a real opportunity to hide their activity inside that noise.
The organizations most exposed are those that have just finished standing up their AI infrastructure and haven’t yet established a baseline for what normal usage looks like. That gap between deployment and monitoring maturity is where infiltration happens.
What this means for developers and security teams
If you’re building on top of AI APIs or running self-hosted models, the threat surface has expanded in specific ways worth tracking:
- API key leakage is now a higher-value target than it was 18 months ago
- Cloud cost anomalies should be treated as a potential security signal, not just a billing issue
- Credential monitoring for AI platform accounts needs the same attention as other SaaS access
- Post-deployment monitoring baselines need to be established quickly, before attackers can blend in
Hultquist’s closing message was direct: organizations that treat AI as a trend they can wait out will find themselves overwhelmed. More incidents, more alerts, more attacks. The window to get controls in place is now, not after the first major breach.



