Skip to main content

Dark Web AI Access: Hackers Score 97% Off

The Black Market for AI Just Got a Massive Discount

Forget coupon codes—cybercriminals have found a way to get premium AI for next to nothing. According to a recent Financial Times report, stolen access to large language models (LLMs) from the likes of Anthropic, Google, and OpenAI is now a hot commodity on the dark web, selling at discounts of up to 97% off. That means instead of paying up to $200 a month for a ChatGPT or Claude subscription, hackers can buy a single stolen login for just a few bucks.

Google's threat intelligence team, led by chief analyst John Hultquist, has seen a sharp rise in what they call "LLM hijacking"—the sale of stolen credentials and the theft of computing power to run models for free. "We're seeing an economic system around AI usage growing rapidly in the underground market," Hultquist said. With 20 years in cybersecurity, he's not easily surprised, but this trend has his attention.

Why does it matter? Because cheap AI gives attackers an edge. "They can obtain these tokens at a much lower price," Hultquist explained. "In the end, these practices give them some kind of economic or efficiency advantage when they fight against us." Some sellers even offer a "guaranteed access" policy: if your stolen account gets banned, they'll hand you a fresh one, no extra charge.

Your Servers Are the New Gold Mine

But it's not just about hijacking accounts. Criminal groups and state-sponsored actors are also sneaking into corporate servers, planting their own AI models to run on someone else's dime—a tactic similar to cryptojacking. As more companies choose to host custom AI on their own hardware instead of renting cloud space, those independent systems become juicy targets.

"If you need to pay for your own computing power, and the cost may be very high... this computing power will become an important potential resource in the eyes of threat actors," Hultquist warned. In other words, your expensive GPUs are now a magnet for hackers.

And there's a timing problem. Many companies are still figuring out how much AI they actually need. For attackers, that confusion is a gift. A sudden spike in computing usage might look like normal activity—after all, you just started using AI, so who's to say what's normal? "You just adopted these AI infrastructures," Hultquist noted. "Indeed, this is an opportunity hidden in the noise."

What Can Be Done?

Hultquist's message is clear: protect your AI infrastructure as fiercely as you'd protect your bank account. That means monitoring for unusual activity, securing credentials, and treating computing power as a valuable asset. Because in the underground market, your AI access is worth more than you think—and someone out there is willing to pay for it.

Key Points:

  • Stolen AI model access is sold on the dark web at discounts up to 97%.
  • "LLM hijacking" involves stolen credentials and theft of computing power.
  • Attackers target corporate servers to run their own AI models for free.
  • Companies' own AI infrastructure is becoming a prime target.
  • Experts urge strong protection of AI systems and computing resources.