Next upAI x Bio Pitch Contest
News

Google details AI credential theft and cloud LLM-jacking

Google Threat Intelligence Group documented stolen AI credentials and a cloud intrusion used to run unauthorized AI workloads. Separate Okta samples show how exposed tokens and API keys can turn victims' paid access into a commodity.

D
Sep 27, 2026 · 2 min read

A September 8 Google Threat Intelligence Group report documents attackers stealing AI credentials and hijacking enterprise cloud infrastructure to obtain costly model access and computing capacity. Its 2026 telemetry included an April intrusion in which an exposed GitHub personal access token gave an attacker entry to an unnamed victim’s cloud environment. The intruder then deployed unauthorized AI infrastructure.

According to GTIG’s account of the Mandiant investigation, the attacker enabled Gemini Enterprise, provisioned high-performance compute and staged LiteLLM and Manus container images. The intruder also exposed Cloud Run services publicly, created a rogue service account with Editor privileges, queried BigQuery for environment variables and credentials, and tried to transfer project ownership to an external email account. GTIG said the attacker requested additional NVIDIA RTX 6000 capacity through the Cloud Quotas API and launched more 48-vCPU instances to sustain the workloads.

GTIG calls this pattern “LLMJacking”: compromising an enterprise cloud environment to run AI workloads on someone else’s resources. In a separate May observation, the group said ACRSTEALER controllers issued file-grabber rules targeting configuration stores used by the Cline and Continue coding assistants. Those files can contain plaintext API keys and custom model-routing endpoints. GTIG also observed at least one North Korea-linked IT-worker cluster using hijacked accounts to register LLM API access in bulk.

The group’s underground-forum tracking showed more buyer personas seeking AI-related accounts in 2026, more sellers advertising them and average per-account prices more than doubling. In that tracked sample, demand centered on Claude and Gemini credentials, with increased interest in coding tools including Cursor Pro and Devin. GTIG did not disclose the number of personas, sellers, listings or prices behind those comparisons. Its observations therefore cannot establish the size of the overall criminal market.

Separate Okta Threat Intelligence research illustrates the credential supply without measuring the wider market. In one 7GB infostealer-log dump released August 2, Okta found 9,213 unexpired Google authentication tokens, 1,763 unexpired Microsoft tokens, 164 unexpired Anthropic tokens and 24 still-valid API keys for Google Gemini, OpenAI, Groq and OpenRouter. The dump contained 5,871 folders representing infected machines across 162 countries. Okta cautioned that its provider counts described only that dataset.

Stolen session tokens can sometimes be replayed to bypass normal password and multifactor-authentication checks. Exposed API keys can charge inference to a victim’s paid quota unless expiration, scope, spending caps or IP restrictions stop the request. In another bounded sample, Okta documented more than 105,000 brute-force signup attempts from 251 IP addresses against one unnamed AI video service between June 1 and July 1. The company assessed the activity as likely bot-driven.

More news