Skip to main content

Hackers Are Snatching AI Accounts on the Dark Web for 70% Off

Illegally grabbing AI models and computing power has become the underground market's hottest commodity. Hackers aren't just after data anymore—they want the expensive brains behind the tools, and they're willing to steal them.

John Hultquist, chief analyst at Google's Threat Intelligence Group, says his team has seen a sharp rise this year in something called "LLM hijacking." Some crooks sell stolen login credentials for public AI tools. Others go further: they break into cloud servers and run their own models for free. Hultquist, a 20-year security veteran, describes a booming "economy centered around AI access" that's growing faster than anyone can track.

Premium Accounts at a Steep Discount

Why pay full price when you can buy a hacked account for pennies on the dollar? On the dark web, stalls are already selling access to models from Anthropic, Google, and OpenAI—with discounts reaching as high as 97%. A premium ChatGPT or Claude subscription can cost $200 a month per person. Underground, it goes for a fraction of that.

And if the account gets banned? No problem. Some sellers offer a "guaranteed access" policy: get shut down, and they'll hand you a fresh set of credentials for free. It's customer service, criminal style.

Breaking In, Running Models, Staying Hidden

Another tactic is even more brazen. Criminal groups—and even state-backed organizations—directly attack cloud servers hosted by companies, install their own AI models, and run them quietly in the background. Think of it like the old cryptojacking schemes, where hackers secretly mined cryptocurrency on someone else's machines. Now they're mining intelligence instead.

Hultquist doesn't mince words: AI has been adopted by "all threat actors," and it's on track to become a core part of every security system. Anthropic's latest abuse report backs this up—actors from more than 20 countries, including the U.S., the U.K., and Yemen, have tried to misuse Claude for malicious purposes.

The Wake-Up Call

If you think AI is just a passing fad, Hultquist has a warning: you'll wake up one day completely overwhelmed. Security incidents, alerts, and attacks will only pile up. "You need to get your side in order now," he says.

The underground market isn't waiting. It's already cashing in.

Key Points:

  • LLM hijacking is on the rise, with stolen AI credentials and computing power sold on the dark web.
  • Discounts reach 97% on premium accounts from Anthropic, Google, and OpenAI; some sellers offer free replacements if banned.
  • Hackers also break into cloud servers to run their own models, echoing past cryptojacking tactics.
  • Threat actors from over 20 countries have misused AI tools, according to Anthropic.
  • Security experts urge immediate action—AI is not a trend to wait out.