Google Threat Intelligence Group discovers dark‑web sales of AI models from Anthropic, Google and OpenAI at up to 97% off
anthropic claude gemini google openai
| Source: Techmeme | Original article
Google's Threat Intelligence Group reports dark‑web markets are offering AI models from Anthropic, Google and OpenAI at discounts of up to 97%, highlighting a rise in LLM‑jacking attacks.
Google’s Threat Intelligence Group (GTIG) has uncovered a surge in dark‑web marketplaces that are selling stolen credentials for leading large‑language‑model (LLM) services at deep discounts – in some cases up to 97 % off retail prices. The illicit listings include access to Anthropic’s Claude, Google’s Gemini and OpenAI’s ChatGPT, as well as to autonomous coding environments such as Cursor Pro and Devin. GTIG’s analysis, reported by the Financial Times, shows that prices for these stolen AI accounts have more than doubled during 2026, reflecting growing demand from threat actors.
The finding signals a new wave of “LLM‑jacking” attacks, where cyber‑criminals hijack costly AI resources to undercut legitimate users and to fuel further malicious activity. Because LLM APIs are billed per token or per request, compromised accounts can generate substantial revenue for attackers while exposing the original providers to reputational and financial risk. The concentration on Claude and Gemini credentials suggests that even providers with robust authentication are vulnerable when credentials are leaked or reused.
Google is responding by expanding its own dark‑web monitoring capabilities. Earlier this year the company launched a Gemini‑powered AI agent that autonomously scans millions of dark‑web posts, flagging data leaks, insider threats and now, AI‑model theft. A broader dark‑web intelligence feature was added to Google Cloud in March, aimed at giving security teams real‑time insight into emerging threats.
What to watch next: the rollout of Google’s enhanced dark‑web intelligence tools in public preview, potential coordinated takedowns of the identified marketplaces, and how AI providers will tighten credential management and usage‑monitoring. Observers will also be keen to see whether law‑enforcement agencies establish dedicated channels for reporting AI‑model theft, mirroring recent “red‑telephone” initiatives for AI risk dialogue.
Sources
Back to AIPULSEN