IntoMobile

Breaking news, information, and analysis on the latest mobile phones and mobile technology

Open NavigationOpen Search
  • Home
  • Platforms
    • iOS / iPhone OS
    • Android
    • Windows Phone
    • BlackBerry OS
  • Hardware
    • New Hardware
    • Tablets
    • Reviews
    • Rumors
  • Carriers
    • AT&T
    • Sprint
    • T-Mobile
    • Verizon
  • Manufacturers
    • Apple
    • Samsung
    • HTC
    • LG
    • Motorola
  • Best VPNs
  • Best AI Tools

Hackers are stealing AI accounts and selling them for 97% off — and it’s getting worse

September 28, 2026 by Dusan Belic - Leave a Comment

Share on Twitter Share on Facebook ( 0 shares )

Someone out there is selling access to Claude and ChatGPT on the dark web for 97% off retail. That’s not a leaked promo code. That’s stolen credentials, and according to Google’s chief threat analyst, this kind of AI account theft is one of the fastest-growing problems in cybersecurity right now.

John Hultquist, chief analyst at Google’s Threat Intelligence Group, told the Financial Times that attacks targeting AI accounts and cloud computing resources have risen sharply this year. The attack method has a name: LLM-jacking. And it’s exactly what it sounds like. Hackers compromise accounts tied to large language models from companies like Anthropic, Google, and OpenAI, then resell that access in underground markets at deep discounts. A Claude Max subscription runs up to $200 a month. On the dark web, someone’s offering the same thing for a few dollars. Some sellers have even introduced “guaranteed access” services, promising fresh credentials if the stolen account gets suspended. That’s not just theft. That’s a whole black-market business model with customer support.

But stolen accounts are only half the story. Hultquist also flagged a second, more aggressive tactic: criminal gangs and state-sponsored groups are breaking into corporate cloud servers and deploying their own AI models directly on the victim’s infrastructure. They use the computing power. The victim pays the bill. The logic is almost identical to the old crypto-mining attacks, where hackers hijacked machines to mint coins without spending on electricity or hardware. The only thing that’s changed is the payload.

This matters because it creates what Hultquist calls a “cost asymmetry” problem. Attackers are getting access to serious AI computing power at a fraction of what it actually costs. Defenders are paying full price to protect themselves. “These practices give them an economic or efficiency advantage,” he said, “because they can acquire that computing power at a much lower cost, while we have to pay full price to defend ourselves.” That’s a structural problem, not just a technical one.

The threat is global and expanding. Anthropic’s latest misuse report found threat actors attempting to exploit Claude in more than 20 countries, including the US, UK, and Yemen. Hultquist was direct about the scale: “Every threat actor is using AI.” That includes ransomware groups, cyber espionage operations, and nation-state hackers.

There’s also a specific vulnerability window that enterprises need to know about. As more companies move away from renting cloud compute and start hosting their own custom AI models on internal servers, those in-house systems become targets. Hultquist pointed out that the period right after a company deploys new AI infrastructure is the riskiest moment. Computing usage spikes naturally during a big rollout, which gives attackers cover to hide their activity inside the noise. By the time anyone notices something’s wrong, the infiltration is already well underway.

The stakes here go well beyond stolen subscriptions. AI computing power is now a commodity valuable enough that criminal organizations are building economic systems around accessing it illegally. The attack surface is growing because AI infrastructure is growing. So the organizations most aggressively adopting AI are, by that same logic, the most attractive targets.

Hultquist’s warning was stark: “Anyone who regards AI as just a passing fad and waits for it to blow over will one day find themselves drowning. They will face more incidents, more alerts, and more attacks than ever before. We must get our house in order now.” That’s not hyperbole from someone trying to sell a product. That’s a 20-year cybersecurity veteran watching the threat evolve in real time and saying the industry is behind.

Share on Twitter Share on Facebook ( 0 shares )

Back to top ▴

Back to top ▴

Copyright © 2006-2021 IntoMobile. All rights reserved.