
Google has identified an increasing cyber threat it labels LLM-jacking, where attackers acquire cloud credentials or API keys and leverage the victim’s paid computing resources to run AI models and automated tools, leaving the account holder to cover the expenses.
The moniker references cryptojacking, a prior method in which cybercriminals commandeered servers to mine cryptocurrency; now, the focus is on the valuable and expensive GPUs required for AI workloads.
How the Attack Unfolds
A typical breach begins with a lapse, such as a personal access token mistakenly committed to GitHub, a leaked API key, or a session token obtained through malware.
Once in possession of the credential, attackers access the victim’s cloud account, activate GPU-intensive virtual machines and AI services, and commence running their models, code assistants, or attack tools.
Account holders often discover the breach when invoices arrive or notice degraded service performance, unauthorized data access, or account suspension.
Google’s Mandiant division investigated a case where an attacker used an exposed personal access token to deploy unauthorized AI infrastructure and scale up high-performance computing, with the customer bearing the cost.
The Bigger Risk
Free computational resources are a key motivator for cybercriminals. Compromised infrastructure allows them to execute or fine-tune models without GPU costs, deploy AI agents for phishing, credential harvesting, and vulnerability scanning, and resell access to hijacked AI accounts while masking their activities.
Exclusive prompts, models, source code, and training datasets may also become accessible once adversaries infiltrate the system.
Unexpected billing charges represent the most visible impact, yet the greater concern lies in a breached account serving as a foothold for lateral network movement, data exfiltration, and automated attacks targeting other organizations.
Google monitors for sudden VM creation, abnormal resource consumption, suspicious API activity, and irregular access patterns, taking action like throttling malicious traffic or isolating affected resources when detected.
What Users Should Do
Individuals managing billable accounts on Google Cloud, AWS, Azure, or AI APIs should prioritize consistent security hygiene.
Ensure credentials and tokens remain out of public code repositories, immediately rotate them if a leak is suspected, and opt for short-lived credentials with minimal permissions.
Activate multi-factor authentication for administrative accounts, set billing limits, configure anomaly alerts, and impose GPU quota restrictions. Regularly review audit logs for new VMs, altered permissions, unfamiliar regions, and unexpected AI usage to shorten an attacker’s operational window.
Separate development, testing, and production environments into distinct accounts to constrain the reach of a single compromised key.
