#LLMjacking
Novel LLMjacking Attacks Target Cloud-Based AI Models

Enter #llmjacking. It was probably inevitable. Threat researchers detected bad actors using stolen credentials to target LLMs, with the eventual goal of selling the access to other hackers.

securityboulevard.com/2024/05/nove...
Novel LLMjacking Attacks Target Cloud-Based AI Models
It was probably inevitable. Threat researchers detected bad actors using stolen credentials to target LLMs, with the eventual goal of selling the access to other hackers.
securityboulevard.com
May 13, 2024 at 6:48 PM
LLMjacking: Stolen Cloud Credentials Used in New AI Attack sysdig.com/blog/llmjack... #infosec #cybersecurity #cloud #ai #llm
LLMjacking: Stolen Cloud Credentials Used in New AI Attack
The Sysdig Threat Research Team found new attack that targets large language model (LLM) services, known as LLMjacking.
sysdig.com
December 30, 2024 at 5:46 PM
LLMjacking an emerging AI threat, stealing access to your paid models and running up bills.

Dan Moore (FusionAuth) likens it to cryptojacking.

Protect yourself with scoped credentials & least privilege. 💻🔒 Read more: www.itbrew.com/stories/what... #LLMjacking #Cybersecurity #Identity #AISecurity
What is LLMjacking, and why should IT pros care?
As anybody who follows cybersecurity knows, when a new technology emerges, it’s usually followed by a threat actor trying to -jack it up. There’s clickjacking (tricking someone into hitting a disguised URL), sessionjacking (stealing a token to impersonate a user and gain their web access), and DNSjacking (redirecting someone to an attacker-controlled destination). And now, with attackers trying to take over large language models, we have…LLMjacking.
www.itbrew.com
September 17, 2026 at 6:54 PM
🚨 LLMjacking attacks are on the rise, now targeting DeepSeek and others! Attackers exploit stolen API keys, racking up massive cloud costs - one ORP instance generated $50K in 4.5 days.

Read: hackread.com/hackers-mone...

#CyberSecurity #AI #LLMjacking #DeepSeek
Hackers Monetize LLMjacking, Selling Stolen AI Access for $30 per Month
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 8, 2025 at 7:53 PM
𝗟𝗟𝗠𝗷𝗮𝗰𝗸𝗶𝗻𝗴 𝗛𝗶𝘁𝘀 𝗗𝗲𝗲𝗽𝗦𝗲𝗲𝗸

sysdig.com/blog/llmjack...
LLMjacking targets DeepSeek
Since the Sysdig team discovered LLMjacking in 2024, we have discovered new methods — including rapid expansion to new LLMs, such as DeepSeek.
sysdig.com
February 7, 2025 at 3:44 PM
🚨 Speaking today at #NHICon Cybersecurity Conference! aembit.io/nhicon/ 🚨

Excited to share that I'll be co-presenting the session "LLMjacking Exposed: How Attackers Hijack AI Models"

🗓 Join us live today www.accelevents.com/e/nhicon

#AI #Cybersecurity #LLMjacking
NHIcon by Aembit
Join NHIcon on Jan. 28, the defining virtual event for non-human identity security, showcasing bold ideas, expert insights, and groundbreaking strategies.
aembit.io
January 28, 2025 at 9:18 AM
Microsoft Disrupts Storm-2139 for LLMjacking and Azure AI Exploitation
Microsoft Disrupts Storm-2139 for LLMjacking and Azure AI Exploitation
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
buff.ly
March 1, 2025 at 7:12 AM
📢⚠️🤖 Operation Bizarre Bazaar has logged 35,000 attacks on exposed AI systems, stealing compute power and reselling access via the underground platform Silver Inc.

Read: hackread.com/operation-bi...

#CyberSecurity #AI #LLM #BizarreBazaar #LLMjacking
Operation Bizarre Bazaar: New LLMjacking Campaign Targets Unprotected Models
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
January 29, 2026 at 5:51 PM
LLMjacking on AWS: How Attackers Abuse Bedrock for AI Token Theft and How to Defend

Introduction: The rapid adoption of Generative AI has created a new attack surface, giving rise to "LLMjacking"—a technique where threat actors compromise cloud credentials specifically to steal large language…
LLMjacking on AWS: How Attackers Abuse Bedrock for AI Token Theft and How to Defend
Introduction: The rapid adoption of Generative AI has created a new attack surface, giving rise to "LLMjacking"—a technique where threat actors compromise cloud credentials specifically to steal large language model (LLM) quota and tokens. Unlike traditional cryptojacking which steals compute cycles for crypto mining, LLMjacking targets AI models hosted on platforms like AWS Bedrock, draining financial resources and potentially accessing sensitive data processed by the models.
undercodetesting.com
March 12, 2026 at 6:39 PM
Documents and sources: insurers including QBE and Beazley are moving to cap cyber policy payouts for losses and regulatory fines tied to AI use and "LLMjacking" (Lee Harris/Financial Times)

Main Link | Techmeme Permalink
April 22, 2026 at 6:30 AM
Hackers used a leaked AWS admin key to create a new IAM user, subscribe to paid AI models through Amazon Bedrock, and pass the inference costs to the victim.

Listen/Read: hackread.com/hackers-hija...

#CyberSecurity #AWS #LLMjacking #AI #Amazon
Hackers Hijack AWS Account to Run Paid AI Models in LLMjacking Attack
FortiGuard Labs details an LLMjacking attack in which hackers used a leaked AWS admin key to subscribe to AI models and generate inference charges.
hackread.com
September 4, 2026 at 1:40 PM
As threat actors pursue LLMJacking more and more (as Permiso found), I’m curious when we’ll see them abusing customer service/customer facing apps. Stealing cloud credentials and using them is hard. Why not just jailbreak LLMs used in web apps for your nefarious purposes?
July 7, 2025 at 10:11 PM
Wanted to separate this part from the main conversation: there are also risks (attack surfaces) that the brand new field of AI OPS is identifying, like LLM-jacking. youtu.be/dibZ1itSvM4?...
April 26, 2025 at 9:26 PM
February 10, 2025 at 12:26 PM
🧵#8 reason for why using a Search engine and using chatGPT is not the same.

ChatGPT can also scout the net for answers, but in doing so it and hereby you might become a victim to prompt injection attack or LLMjacking.
LLM01: Prompt Injection Explained With Practical Example: Protecting Your LLM from Malicious Input
Prompt Injection in AI: Common Attack Scenarios and How to Mitigate Them
medium.com
January 11, 2025 at 5:22 PM
🧵#10 reason for why using a Search engine and using chatGPT is not the same.

Circling back to #8 and supplying context and info on LLMjacking.

Due to the way LLMs work bypassing guardrails and safeguarding is almost always a possibility. The same reason you can do it yourself when using them.
What is LLM Jacking? | Wiz
LLM jacking is an attack technique that cybercriminals use to manipulate and exploit an enterprise’s cloud-based LLMs (large language models).
www.wiz.io
January 11, 2025 at 5:37 PM
🚨 Microsoft Discupts Storm-2139 for LLMjacking & Azure AI Exploitation - Hackers hijacked AI models using stolen API keys.

🔗 hackread.com/microsoft-st...

#CyberSecurity #AI #LLMjacking #Microsoft
Microsoft Disrupts Storm-2139 for LLMjacking and Azure AI Exploitation
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 28, 2025 at 8:59 PM
Operation Bizarre Bazaar: First Attributed LLMjacking Campaign with Commercial Marketplace Monetization

Interesting read

cybersec.pillar.security/s/operation-...
Operation Bizarre Bazaar
Our research team discovered a complete LLMjacking supply chain. Attackers scan for exposed AI endpoints, validate access through systematic API testing, then resell discounted access to compromised infrastructure...
cybersec.pillar.security
February 2, 2026 at 2:58 PM
The Growing Dangers of LLMjacking: Evolving Tactics and Evading Sanctions https://groups.googl... #machinelearning #ai
September 21, 2024 at 5:49 AM
CyberDudeBivash Cyber Incident Analysis Report - LLMjacking (Operation Bizarre Bazaar)

Read the full report on - cyberbivash.blogspot.com/2026/02/cybe...
CyberDudeBivash Cyber Incident Analysis Report - LLMjacking (Operation Bizarre Bazaar)
CyberDudeBivash offers real-time cybersecurity news, threat intelligence, zero-day vulnerabilities, malware reports, and security tools.
cyberbivash.blogspot.com
February 2, 2026 at 2:20 AM
New from Pillar Security: "Operation Bizarre Bazaar: First Attributed LLMjacking Campaign with Commercial Marketplace Monetization" cybersec.pillar.security/s/operation-...
Operation Bizarre Bazaar
Our research team discovered a complete LLMjacking supply chain. Attackers scan for exposed AI endpoints, validate access through systematic API testing, then resell discounted access to compromised i...
cybersec.pillar.security
January 29, 2026 at 3:18 PM
Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries thehackernews.com/2026/01/rese...
Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries
Over 175,000 publicly exposed Ollama AI servers across 130 countries, with many enabling tool calling that allows code execution and LLMjacking abuse.
thehackernews.com
January 31, 2026 at 9:12 PM