tech
Researchers Warn Hackers Are Hijacking Companies' AI Accounts

Security researchers are warning of a surge in "LLM-jacking," a form of cybercrime in which hackers hijack companies' artificial intelligence accounts and servers to exploit computing resources that would otherwise cost the attacker money, according to the Financial Times. The stolen access is being used directly by attackers or resold, feeding what researchers describe as a growing cybercrime economy built around corporate AI capacity, the FT reports.
What Is LLM-Jacking?
The term refers to the theft of access to large language models, or LLMs, the AI systems that power chatbots and other generative tools. Instead of stealing data outright, attackers in these cases take over accounts or servers that already have paid access to AI compute — the processing power needed to run AI queries — and use that access for their own purposes, per the FT's reporting.
Why Are AI Accounts a Target?
Running large AI models is expensive. Companies pay providers for computing capacity by usage, and that capacity has real market value. Security researchers cited by the FT say this cost structure is precisely what makes hijacked AI accounts attractive: an attacker who gains control of a victim's account can consume expensive compute resources without paying for them, shifting the bill to the legitimate account holder.
What Happens to Stolen AI Access?
According to the FT, stolen access is either used directly by the hackers who obtained it or resold to other parties, effectively creating a secondary market for hijacked AI capacity. That resale dynamic is what researchers point to as evidence of a broader cybercrime economy forming around AI infrastructure rather than isolated, one-off intrusions.
How Does This Fit Into the Wider AI Cost Picture?
The value of AI compute has become a running theme across the industry as companies weigh how to price access to their models. Meta, for instance, has rolled out new AI-focused subscription tiers as it looks to monetize consumer access to its AI tools, according to HTT News. That broader push to attach a price tag to AI usage underscores why hijacked access to that same infrastructure carries resale value on the criminal side, even though the Meta subscription rollout itself is unrelated to the hijacking cases described by the FT.
Glossary
LLM-jacking: The unauthorized takeover of an account or server with access to a large language model, used to run AI workloads at the victim's expense.
Large language model (LLM): An AI system trained on large volumes of text data to generate human-like responses, the technology underlying most modern chatbots.
Compute resources: The processing power, measured and billed by usage, required to run AI queries and training jobs.
The FT's report does not name specific victim companies or attackers, and researchers cited in the piece frame the activity as an emerging pattern rather than a single incident. HTT News will update this report as further documentation of specific cases becomes available.
Questions
What is LLM-jacking?
It is the unauthorized takeover of a company's AI account or server, allowing attackers to use paid AI computing resources without paying for them, according to the Financial Times.
What do hackers do with hijacked AI access?
Researchers cited by the FT say stolen access is either used directly by attackers or resold to others, creating a market for hijacked AI capacity.
Why are AI accounts valuable to hackers?
Running large AI models is costly, so gaining free access to a victim's paid computing capacity has direct financial value to attackers, per the FT report.