// ZDNET — INTELLIGENZA ARTIFICIALE
LLMjacking can run up your business’ AI bill fast – how to stop it
Google analysts warn that stolen AI credentials are being sold underground, and businesses are footing the bill.
Security experts warn that it’s not just artificial intelligence (AI) going rogue that we have to worry about — there’s also a booming underground economy for selling access to your AI models and computing power.
Speaking to the Financial Times, John Hultquist, chief analyst for Google Threat Intelligence Group, said that the cybersecurity unit has seen a “major increase” in what is known as LLMjacking over 2026, a trend that could cost businesses dearly.
If cryptojacking came to mind, you’re on the right track. While cryptojacking describes stealing computing power to illicitly mine cryptocurrency, LLMjacking is the AI equivalent: using AI power and resources that don’t belong to you.
Also: OpenAI’s Dots: Like OpenClaw declawed – for $200/mo ChatGPT Pro users
In the cybercriminal world, this means trying to secure credentials or API keys that give a criminal authorized access to business AI accounts, which often have high usage limits, or potentially none at all — with token overspill charged outside of typical subscription costs.
Cybercriminals can obtain username and password combinations or API keys by gaining access to a corporate network, stealing them via phishing, data breaches, vulnerabilities, or insider threats. This grants cybercriminals the opportunity to use an AI model without paying for the tokens themselves, for reasons such as:
Once stolen, credentials and API keys can also be sold on the underground to other cybercriminal groups.
As AI models offered by organizations, including OpenAI and Anthropic, continue to advance in sophistication, capacity, and skill, they require more computing power.
The more power you need, the more tokens you need to purchase — or the higher the level of subscription you must purchase.