Access to frontier AI models has become a commodity on the criminal internet. John Hultquist, chief analyst at Google's Threat Intelligence Group, told the Financial Times that underground marketplaces are now selling access to commercial models from Anthropic, Google and OpenAI at discounts of up to 97% off list price — a subscription that normally costs as much as $200 a month at the top tier.
The trade has professionalized quickly. Because AI vendors actively monitor their platforms for abuse and shut down accounts, several sellers now bundle a "guaranteed access" service: if the original credentials get banned, buyers receive replacement ones at no extra cost. Payment runs through cryptocurrency, and listings circulate on hidden forums rather than open web shops.
Alongside the resale market, Google's researchers are tracking a more direct technique the industry has started calling "LLM-jacking." Instead of buying access, criminal groups and state-aligned actors compromise cloud-hosted servers, install their own AI models, and run inference on someone else's bill — a playbook that mirrors the cryptojacking waves of the last decade, with GPU hours instead of mined coins as the prize.
"What we are seeing in underground markets is a growing economy forming around access to AI," Hultquist said. The economics are lopsided: attackers obtain top-tier model access at a fraction of retail cost, while defenders pay full price for the same capability — and the asymmetry compounds when the stolen compute powers phishing, malware generation or disinformation at industrial scale.
The demand side is not hypothetical. Anthropic's most recent quarterly threat report said it had identified threat actors in more than twenty countries — including the United States, the United Kingdom and Yemen — attempting to misuse its Claude models for operations ranging from influence activity to malware development. Every major lab now publishes similar disclosures on a rolling basis, and none suggests the trend is slowing.
"Every threat actor is using AI," Hultquist said. For enterprises, the practical takeaway is unglamorous: treat API keys and model subscriptions like credentials worth stealing — because on the dark web they now are, priced, discounted, warranted and resold.
Comments (0)
Log in to join the discussion
Log InNo comments yet