Imagine logging into your cloud dashboard on a Monday morning and discovering a six-figure AI inference bill — for workloads you never ran. That's not a hypothetical. It's the lived reality of businesses falling victim to LLMjacking, one of the fastest-growing cyber threats targeting organisations that use AI services. If your business is plugged into cloud-hosted large language models (LLMs) like AWS Bedrock, Azure OpenAI, Google Vertex AI, or Anthropic's Claude, you need to understand this threat now — before the bill lands in your inbox.


What Is LLMjacking?

LLMjacking describes threat actors using stolen cloud credentials to gain access to a victim's paid AI model services and leverage the compute power, leaving the victim to pay the bill.

LLMjacking as a distinct threat category entered the security lexicon in May 2024, when Sysdig's Threat Research Team (TRT) published the first documented case of an attacker using stolen cloud credentials to hijack access to hosted AI inference services.

LLMjacking follows the same pattern as two older attack categories: cryptojacking — where stolen compute resources are used to mine cryptocurrency — and proxyjacking — where stolen bandwidth is resold. In LLMjacking, stolen AI API credentials are used to run large language model inference at the victim's expense, either for the attacker's own use or resold to third parties on illicit marketplaces.

What makes this attack uniquely dangerous is the speed and scale of financial damage it can inflict — and the fact that it has evolved dramatically in sophistication since it first appeared.


The Anatomy of an LLMjacking Attack

Understanding how attackers pull this off is the first step to stopping them.

Step 1: Credential Theft

Attackers did not stumble into AI API keys accidentally; they actively scanned public code repositories, misconfigured CI/CD pipelines, and exposed environment variable endpoints for credentials specific to AI services.

A developer sets an environment variable locally, tests the integration, and accidentally commits the .env file — or hardcodes the key directly in the source to "test quickly" and forgets to remove it before pushing. The repository is public. Within minutes, automated scanners operated by criminal groups and independent researchers are indexing that commit and extracting the credential.

Attackers also exploit unpatched web application vulnerabilities.

In one documented case, credentials were obtained from a system running a vulnerable version of Laravel (CVE-2021-3129).

Step 2: Reconnaissance Without Detection

Once inside, attackers don't simply start burning through your quota.

No legitimate LLM queries were actually run during the verification phase. Instead, just enough was done to figure out what the credentials were capable of and any quotas. Logging settings are also queried where possible — done to avoid detection when using the compromised credentials to run their prompts.

Attackers use automated scripts to test stolen credentials against multiple AI services, check quota limits and available spending capacity, determine which models they can access, and verify the credentials work without triggering immediate alerts.

Step 3: Monetisation at Your Expense

In an LLMjacking attack, threat actors use stolen cloud credentials to gain illicit access to an organisation's LLMs. Sometimes the motive is personal use, but increasingly the point is to sell unauthorised access to third parties, including entities who've been banned from a given LLM service, or are located in sanctioned countries.

The criminal infrastructure consists of a three-stage supply chain — automated reconnaissance using Shodan and Censys, quality-based endpoint validation, and commercial resale — culminating in underground marketplaces that resell unauthorised access to more than 30 LLM providers at 40–60% discounts via Telegram and Discord, accepting cryptocurrency and PayPal.


The Financial Damage Is Staggering

This isn't a theoretical risk — the costs are eye-watering and immediate.

The initial campaign targeted ten commercial AI providers including AWS Bedrock, Azure OpenAI, Anthropic, and Google Vertex AI, and Sysdig estimated the financial exposure to victims at over $46,000 per day for Claude 2.x-class inference.

Attackers monetising access through reverse proxies have reportedly inflated victim costs to as much as $100,000 per day.

And the scale of these attacks is only growing.

Between December 2025 and January 2026, security researchers discovered a disturbing evolution in AI-targeted cyber threats: honeypots recorded 35,000 attack sessions targeting exposed AI infrastructure, averaging 972 attacks per day.


LLMjacking Has Gone from Opportunistic to Industrial

By early 2026, LLMjacking had become commercialised. Since its emergence in May 2024, LLMjacking has evolved from a novel security concern into an industrialised cybercrime marketplace.

The danger now extends well beyond your cloud bill.

Attackers have wired access to AI tools into software pipelines that scan a target, match it to known vulnerabilities, write proof-of-concept exploits, and attempt to break into a victim's environment — with the model making decisions at every step.

Data exfiltration via LLM context windows can include sensitive organisational data such as call history, customer information, and source code. Exposed MCP servers become entry points for attackers to use LLM integrations to navigate file systems, query databases, and access cloud APIs.

In other words, what started as a billing scam has become a potential full-scale breach vector.


How to Detect LLMjacking in Your Environment

Early detection is critical. Here are the warning signs you should monitor:

evolving attacker tactics include enabling LLMs via APIs and tampering with logging configurations, such as deleting model invocation logging, to evade detection.

attackers have been observed creating brand-new IAM users inside the victim's account and using them to subscribe to foundation models available through cloud marketplaces.

evidence of a reverse proxy for LLMs being used to provide access to the compromised accounts is a strong indicator of LLMjacking activity.


Practical Tips: How to Stop LLMjacking Today

You don't need a six-figure security budget to start protecting your business. Here are actionable steps you can implement right now:

🔑 1. Treat AI API Keys as Tier-Zero Credentials

LLM credentials are now becoming business-critical secrets that must be governed like cloud keys. Treat LLM API keys as tier-zero credentials and assign an explicit owner.

🔄 2. Rotate Keys Regularly and Retire Unused Tokens

Rotate API keys on a schedule and retire unused tokens. Use short-lived tokens tied to a single service instead of broad, long-lived secrets. Bind each key to its job — limit it to a specific app or IP range, or set an approved network path to your LLM provider so a leaked key can't last long.

🔍 3. Scan Your Codebase for Exposed Secrets

With 29 million new secrets exposed on public GitHub in 2025 — a 34% year-on-year increase — best practices include enforcing least privilege, rotating credentials every 30–90 days, using vault-backed storage, and never hardcoding keys in source code or environment variables in production.

🔒 4. Implement Strong Authentication Beyond API Keys

For servers handling remote requests, implement robust authentication and authorisation rather than relying solely on API key validation. Solutions based on OIDC or OAuth2 with short-lived tokens are the most effective. This not only defends against LLMjacking, but also allows for more granular tracking of user activity and prevents API key abuse.

🌐 5. Apply Network Segmentation and Least Privilege

Use network segmentation and IP allowlists to give AI server access only to the departments, employees, and services that require it. Apply the principle of least privilege by separating access to specific services — for instance, MCP and LLM components should have their own distinct access tokens.

📊 6. Set Cost Alerts and Usage Quotas

Add cost guardrails (quotas) and alerting as a backstop

for detecting anomalous usage. Most cloud AI providers — including AWS, Azure, and Google Cloud — allow you to set hard spending limits and email/SMS alerts when thresholds are crossed. This won't prevent an attack, but it will dramatically reduce the financial blast radius.

🛡️ 7. Segment Keys by Environment and Workload

Segment keys by environment and workload, avoiding shared "global" keys. Rotate keys quickly when exposure occurs, and assume commit history persists even after "removal."


Conclusion: Don't Let Attackers Cash In on Your AI Investment

Your business's investment in AI should be driving value for you — not funding a criminal marketplace. LLMjacking is a clear and present danger for any organisation using cloud-hosted AI services, and the barrier to entry for attackers has never been lower. The good news is that the defensive steps are well within reach for businesses of every size.

Start today: audit where your AI API keys live, rotate any credentials that haven't been cycled recently, enable spending alerts on every cloud AI account, and scan your repositories for accidentally committed secrets. If you'd like a comprehensive review of your organisation's cloud security posture — including your AI infrastructure — get in touch with our team now. Our security experts can help you lock down your environment before attackers find the door you didn't know you'd left open.