On September 28, IT Home reported a Financial Times article from the 26th. Illegally obtained AI models and compute are becoming sought-after goods on criminal markets, the report says. John Hultquist, chief analyst at Google's threat-intelligence group, says so-called LLM hijacking has increased markedly this year. He means two things: resale of stolen logins for public AI tools, and groups that take someone else's compute to run their own models for free.

Hultquist says an underground trade in the right to use AI is growing. Attackers can buy tokens that are otherwise expensive, at a much lower price. Defenders, he says, often need the same tools to respond.

[1]
Aquatint of a pile of identical unmarked keys beside a locked cabinet.
The keys have no marks, and the cabinet is locked. They stand for access being resold, and this is not a screenshot of a listing., AI-generated illustration, not a news photograph

Researchers at Google's threat-intelligence group found dark-web listings for access to models from companies including Anthropic, Google, and OpenAI, with discounts as high as 97 percent. For comparison, IT Home says the top subscriptions for ChatGPT and Claude can cost 200 dollars per user per month, and it notes about 1,346 yuan at the exchange rate it cites. That monthly price is the report's official comparison, not a dark-web price tag.

Hultquist says labs watch for abuse, so some sellers offer guaranteed access: if the first account is banned, they do not charge again and hand over new login credentials. Other criminal groups, and some state-backed groups, break into servers a company hosts in the cloud, install their own model, and run it on the victim's machines. The report compares that to mining cryptocurrency on someone else's hardware.

[1]

Hultquist also says more large companies want custom models on their own servers, rather than renting compute from a cloud provider. Those self-run systems become targets, because the compute itself is what the attacker wants. He thinks companies are still learning how much AI they need, so a sudden jump in usage is easy to treat as normal. That, he says, is the opening for slipping into accounts and servers.

This is one analyst's account to the Financial Times, as carried by IT Home. This piece did not open the Financial Times, and it does not have the original dark-web listings. The 97 percent figure is the highest discount in the report, not the price of every sale. The yuan figure is IT Home's exchange-rate note.

[1]

要点

  • Hultquist says resale of stolen model logins, and free use of other people's compute, increased this year.
  • Dark-web listings offer access to Anthropic, Google, and OpenAI models at discounts up to 97 percent.
  • Some sellers promise a fresh login at no extra charge if the first account is banned.
  • Others install a model on a company's cloud servers. The 97 percent figure is the top discount, not every price.