Stolen AI Is a Market Now

Status: Analysis / LLM-jacking, September 2026

Google Threat Intelligence Group, Mandiant, Okta and Anthropic (September 2026)


CISO Perspective: Stolen AI access is now a market, with a 97% discount and a replacement guarantee, and attackers run their own models inside victims’ cloud accounts where the spend hides in normal AI growth. Five kinds of AI act in an environment without anyone authorizing it, and every one of them ran on a valid credential. Identity says a key was used. Only a check on the action says whether what it is doing is allowed.

  • Date. September 2026. Google Threat Intelligence Group report September 8, Okta September 9, Mandiant September 16, John Hultquist in the Financial Times September 27.
  • Type. Credential theft and cloud hijacking for AI compute (LLM-jacking), plus hijacked, runaway and unsanctioned agents acting inside company environments.
  • What happened. Dark web sellers offer model access at up to 97% off. One exposed GitHub token became Gemini Enterprise, an agent framework and GPU quota requests inside a victim’s cloud. An attacker’s agents harvested thousands of credentials in under six hours. A hijacked coding assistant spread a worm through about 100 repositories. An accounting agent ran up about $50,000 in under an hour with no attacker at all.
  • Where the gap is. Every case ran on a valid credential. A replayed token skips the password and the MFA challenge, and the actions looked like ordinary AI usage on the company’s own bill.
  • Why it matters to us. The check has to sit on the action, whoever started the agent and whatever model runs it. The inventory has to exist first, or the spike has no baseline to stand out against.

John Hultquist runs analysis at Google’s Threat Intelligence Group, and this weekend he told the Financial Times that attacks on AI accounts and AI compute have surged this year. The dark web now sells access to models from OpenAI, Anthropic and Google at up to 97% off. A plan that costs $200 a month goes for a few dollars. Some sellers offer a guarantee: if the account gets suspended, you get a replacement free. The trade has a name, LLM-jacking, and Google’s own tracker says buyer demand for Claude and Gemini credentials more than doubled in 2026.

For anyone defending a company, the discount is not the number that matters. Hultquist put it this way: “They can acquire that computing power at a much lower cost, while we have to pay full price to defend ourselves.” He also said attackers can “hide within the normal increase in computing activity as companies expand their AI infrastructure.” Your AI bill is going up anyway. Nobody is going to notice the part of it that is theirs.

Google’s report carries one case in detail. In April an attacker found an exposed GitHub personal access token. With it they turned on Gemini Enterprise inside the victim’s cloud, stood up an agent framework on the victim’s serverless platform, asked the quota API for NVIDIA RTX 6000 GPUs, and launched 48-vCPU instances to run their own AI workloads. Every step ran under the victim’s identity, inside the victim’s account, on the victim’s invoice. To the cloud provider it was a customer using AI.

That is one way an AI nobody authorized ends up acting in your environment. There are four more, and September produced a case for each.

An attacker’s own agents, run against you. Google watched a financially motivated crew hand an AI coding chatbot a set of markdown playbooks and let it go. The agents ran the scanning pipeline, fixed their own errors, rotated IP addresses when blocked, and compromised thousands of third-party credentials. Start to finish, under six hours. Hultquist: criminals “will gravitate to attacks that are faster than we can respond to.” A separate operation left its dashboard exposed, and inside it were more than 23,800 stolen secrets, cloud keys and AI service keys among them.

Your own agent, hijacked mid-session. Mandiant responded at a SaaS company where an attacker got into a developer’s live AI coding assistant session. The assistant recommended a poisoned package. The developer accepted it. From there the attacker took GitHub OAuth tokens and pushed the Shai-Hulud worm through about 100 internal repositories, then infected a second employee with a poisoned package in the company’s own namespace. The worm stole repository secrets and product source code. The developer’s own assistant did the attacker’s work, with the developer watching.

Your own agent, off the rails with no attacker at all. Also from Mandiant: an accounting automation entered a runaway loop and made more than 15,000 high-cost API calls in under an hour. About $50,000 in cloud charges, and live business transactions disrupted while it ran. Nobody broke in. The agent just kept going.

AI your people brought from home. Mandiant lists “unmanaged open-weight model deployments” as one of its risk categories this year, and every security team already knows what that means in practice. A team stands up a model on a spare GPU box. An engineer pays for their own coding agent and points it at the repo. A manager wires a third-party agent into the ticket queue over a weekend. None of it is malicious. None of it is inventoried, either, and none of it is checked.

Every one of those five cases ran on a valid credential. The stolen GitHub token was real. The hijacked session was authenticated. The runaway agent had exactly the permissions it was granted. The engineer’s personal coding agent used the engineer’s own access.

Okta’s threat team put a number on how cheap that is to get. A 7 GB infostealer dump released on Telegram in August held logs from 5,871 machines in 162 countries. In it were 44,791 session tokens, 555 of them for AI services, and 1,843 still valid the day the dump went public. As Jeremy Kirk at Okta put it, attackers want tokens because “it is often possible to replay those secrets and bypass credential-based authentication.” A replayed token does not see the password prompt or the MFA challenge. Anthropic’s September misuse report says the same thing from the other side: stolen keys, tokens and devices have “increasingly become the sole objective of multiple criminal groups,” and one group went from a single stolen developer token to full cloud admin in roughly three hours.

So identity tells you a key was used. It does not tell you whether the thing holding the key is your agent, your agent under someone else’s control, or an agent that was never yours. And it says nothing about what the key is being used to do.

Two things. In this order.

You can see every AI running in your environment, including the ones nobody registered. OWASP and NIST both say keep an inventory of your agents, and it is easy to read that as paperwork. Hultquist just explained why it is not. If attacker load hides inside your own AI growth, the only way to see the spike is to know the baseline: which agents, which models, which keys, which compute, sanctioned or not. Shadow AI used to be a data leakage problem, an employee pasting a contract into a chatbot. It is now an execution problem. The agent someone brought from home can push code, move money and delete tables, and so can the one an attacker stood up on your GPUs.

Every action gets checked before it runs, whoever started the agent and whatever model it runs on. This is the part identity was never built to do. Dropping database tables, pushing a package into 100 repositories, requesting GPU quota, firing 15,000 API calls in an hour: each of those is an action, and a rule written in plain English about the action does not care who typed the prompt or which model wrote the command. A valid token answers “may this key be used.” A check on the action answers “may this action run, for this agent, right now.” Those are different questions, and September’s cases all lived in the gap between them.

Mountain Theory sits between the AI’s decision and its execution. Every action an agent is about to take is checked against rules written in plain English, before it runs. Allowed, held, or blocked. Every decision logged. It works with any AI you use, which in this context means it does not matter whether the model was yours, stolen, or brought in from home.

I am not going to tell you it would have stopped any of the cases above. I did not run them. I can tell you what a check on the action is built to hold or stop. A run of retries past a cap. An action outside the task the agent was given. A credential or a customer record leaving your environment. An action nobody has written a rule for yet, held for a decision instead of allowed through. A blocked action tried again by a different route.

The model still decides. The action does not run until it has been checked. Someone else’s AI on your bill is still an agent taking actions in your environment, and that is the layer you can control.

Sources. John Hultquist to the Financial Times, “Hackers hijack AI accounts and servers to fuel new cyber crime boom” (September 27, 2026), as carried by PYMNTS and others. Google Threat Intelligence Group, “GTIG AI Threat Tracker: From Prompting to Autonomy” (September 8, 2026). The Hacker News on the six-hour campaign (September 8), on Okta’s token research (September 9) and on the hijacked coding assistant (September 16). Mandiant, AI Risk and Resilience (September 16, 2026). CSO Online, Lucian Constantin (September 15, 2026). Anthropic, Detecting and countering misuse of AI: September 2026. The attacker-side companion piece is here.

A valid credential proves a key was used. It does not say whose agent is holding it or what that agent is doing. Inventory what runs, then check each action before it runs, whichever model is behind it.

See it on your own agents. Book a demo.

Scroll to Top