Google threat intelligence: dark-web markets sell access to OpenAI, Anthropic and Google models at up to 97% off; LLM-jacking surges
On Sept 27, 2026 the FT reported findings from Google's Threat Intelligence Group that dark-web marketplaces are selling unauthorized access to models from OpenAI, Anthropic and Google at discounts of up to 97%, and that "LLM-jacking" (stealing credentials or hijacking cloud servers to run models at the victim's expense) grew sharply in 2026.
Key facts
- Access to OpenAI, Anthropic and Google models sold at up to 97% below list price; some sellers offer free replacement accounts if banned
- John Hultquist (chief analyst, GTIG): 'What we're seeing in the underground market is a burgeoning economy centered on AI access'
- Attackers also breach enterprise cloud servers to run models on the victim's bill, similar to cryptojacking; used by criminals and an active Chinese espionage group
- Victims may mistake attacker compute spikes for normal AI demand
What happened
Google's threat researchers told the Financial Times that stolen or resold access to premium AI services has become an established underground product, alongside the older practice of hijacking cloud accounts to run models for free.
Why it matters
It shows frontier-model access becoming a commodity for criminals, which matters for misuse safeguards that depend on account-level monitoring and bans.
Caveat: the FT article is paywalled; details come from secondary coverage.
Changelog
- 2026-09-29: created (sweep 2026-09-29)
Related events
Sources (2)
- pressFT: dark web markets sell access to AI models at steep discounts
- pressDataconomy: Google warns of surge in AI account theft and LLM-jacking attacks
id: 2026-09-27-google-gtig-dark-web-ai-access-llmjacking · updated 2026-09-29 · open in the interactive timeline