AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Buying for a business?Offer from Amazon

Get business pricing on office and shipping supplies

  • Business-only prices and quantity discounts
  • Tax-exempt purchasing
  • Multiple users, one account, clear invoices
As an affiliate, we earn on qualifying purchases.

The Financial Times reports that cybercriminals are increasingly buying stolen credentials and computing access to use commercial AI models at reduced cost. Google Threat Intelligence Group analyst John Hultquist says the activity is growing, while companies also report AI-generated vendor impersonation as a leading threat.

Cybercriminals are increasingly trading access to artificial intelligence models, including stolen credentials and computing resources, according to a Financial Times report published Sept. 27. John Hultquist, chief analyst at Google Threat Intelligence Group, told the newspaper that the activity is growing as attackers seek to use costly large language models for extortion, warfare and espionage.

The Financial Times report, citing Google Threat Intelligence researchers, said dark web marketplaces offer access to models from Anthropic, OpenAI and Google at discounts of up to 97%. The report described two routes into this market: sales of pilfered login credentials for public AI services and theft of computing resources that allow groups to run models without paying standard prices.

Some of the most advanced AI subscriptions from OpenAI and Anthropic can cost as much as $200 per user each month, according to the report. Hultquist told the FT that cheaper access can give attackers an economic or efficiency advantage over organizations that must defend against them. The cited discount figure describes offers reported in the underground market; it does not establish how many offers are available, how often they work, or how widely they are used.

Separately, PYMNTS Intelligence research cited by PYMNTS says 42% of surveyed companies use three or more AI defense tools as part of a layered security stack. Half identified AI-generated vendor impersonation emails as their leading threat. The research also found that close to 90% of finance leaders considered vendor verification a moderate or major burden. These figures concern companies’ reported defenses and concerns; they do not measure the scale of illicit AI access.

At a glance
reportWhen: Reported September 27, 2026; Google Thr…
The developmentA Financial Times report says illicit access to commercial AI models is becoming a growing underground market for cybercriminals.

Cost Pressures on Cyber Defenses

The reported trade matters because access to capable AI may affect the cost and speed of cyber operations. If attackers can use stolen accounts or computing resources at lower prices, defenders may face activity supported by tools that would otherwise require substantial spending. Hultquist’s warning is that this creates an economic imbalance, though the report does not quantify how much it has changed attack frequency or outcomes.

Companies are also adopting AI for defense while confronting AI-assisted impersonation. The PYMNTS survey figures point to pressure on finance teams responsible for checking vendors and payment requests. Organizations may therefore need to account for both risks: unauthorized use of AI services and fraud attempts that use generated messages to imitate legitimate contacts.

Amazon

Top picks for "acces becom commodity"

As an affiliate, we earn on qualifying purchases.

The Market Behind AI Access

LLM-jacking is the term used in the report for unauthorized use of AI models or the computing resources needed to run them. The reported activity includes credential theft and resource theft, which can shift model costs onto account holders, service providers or owners of compromised infrastructure. The report identifies extortion, warfare and espionage as intended uses attackers are pursuing, but it does not detail specific operations tied to the marketplace.

Commercial AI services have paid subscription tiers, with some high-end plans reaching $200 per user per month. That pricing helps explain the incentive to seek cheaper access, but it does not by itself show how much criminals save in practice. The parallel PYMNTS Intelligence research reflects a separate development: companies are adding AI-based security tools even as respondents identify AI-generated impersonation as a prominent concern.

“Catching these fraud attempts is hard work, costing firms time and money.”

— PYMNTS Intelligence report, “Prevention First: Building a Smarter Defense Against Payments Fraud”

Scale of Illicit Access

The reporting does not establish how many accounts or computing resources have been compromised, how many buyers use the advertised access, or whether the reported discounts are typical across marketplaces. It also does not quantify the share of cyberattacks involving illicit AI access or show that access has directly caused a measured rise in successful attacks.

The PYMNTS survey findings are company responses, not a count of confirmed fraud incidents. The source material does not specify the survey sample size or field dates, and it provides no evidence linking those reported vendor impersonation concerns to the marketplace activity described by the FT.

Security Teams Track Access

Google Threat Intelligence Group’s account points to continued monitoring of stolen credentials, unauthorized resource use and underground sales. The source material gives no specific enforcement action, service change or upcoming report date. Companies’ immediate security challenge remains limiting account compromise and checking vendor requests while assessing how AI tools affect both attack methods and defensive workloads.

Further reporting would be needed to establish whether marketplace access is expanding, which services are most affected and whether providers or law enforcement are disrupting the trade. Until those details emerge, the reported discounts and observed increase should be treated as indicators described by researchers, not a complete measure of the market.

Key Questions

What is LLM-jacking?

In the report, LLM-jacking refers to unauthorized access to AI models or computing resources, including the use of stolen credentials or stolen capacity to run models.

Which AI companies were named in the report?

The Financial Times report cited dark web offers for access to models from Anthropic, OpenAI and Google.

How large were the reported discounts?

The report said some marketplace offers were discounted by up to 97%. It did not establish how common those offers are or whether they consistently provide working access.

What cyber threat did surveyed companies identify?

In research cited by PYMNTS, 50% of companies surveyed identified AI-generated vendor impersonation emails as their leading threat. The figures reflect survey responses, not confirmed incident counts.

Source: rss

This content is for general information only and is not financial, tax or legal advice. Consult a qualified professional for decisions about your money.
FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Vantage Amplia L’offerta Di CFD pre-IPO Con Unitree Robotics, Mentre Cresce L’interesse Per l’IA Di Frontiera

Vantage annuncia l’espansione dell’offerta di CFD pre-IPO includendo Unitree Robotics, segnalando un crescente interesse per l’IA e i robot autonomi.

Reopening Of Five-year Federal Notes (Bundesobligationen – “Bobls”) – Auction Result

Germany’s Bundesbank has announced the reopening of five-year federal notes (Bobls) through an auction, marking a significant step in debt issuance strategy.

The Essential Bet: Recursive Self-Improvement In AI Innovation

AI research is now focusing on recursive self-improvement, with labs and companies demonstrating early capabilities toward automated AI self-enhancement, but full loop closure remains unachieved.

2026 AI Supplier Highlights: Europe’s Most Influential Companies

An overview of the most influential European AI companies in 2026, focusing on ownership, certification, and strategic significance for sovereignty.