Mostly True
Cybercriminals are increasingly stealing other people's AI accounts and servers to run large language models (LLMs) at someone else's expense, a scheme known as 'LLM jacking.' The practice lets attackers tap paid AI services and computing resources without paying, and it is spreading as generative AI adoption grows.
LLM jacking typically involves attackers obtaining stolen credentials for cloud or AI service accounts, then using those accounts to access LLM services. In some cases, compromised servers are converted into unauthorized computing resources for running AI workloads. The victims are billed for the usage, while the attackers receive AI capabilities for free.
The scheme is attractive to criminals because legitimate access to powerful LLMs and the GPU infrastructure behind them can be costly, and stolen access effectively transfers that cost to account holders.
For ordinary users and businesses, an LLM jacking incident can mean unexpected charges, service suspension, and the exposure of data stored in compromised accounts. Security guidance circulated with the reports emphasizes credential protection — strong, unique passwords, multi-factor authentication, and monitoring of usage and billing records — as the main line of defense.
Authorities and security researchers note that the scale of the problem is still unfolding, and the full extent of LLM jacking incidents remains unclear as attacks often go undetected until charges appear.
The rise of LLM jacking underscores a broader point: as AI services become a standard business tool, the accounts and servers that power them have become targets in their own right, much like cloud infrastructure before them. Companies offering AI services face pressure to harden authentication and detect abnormal usage patterns, while users are urged to treat AI accounts with the same care as financial ones.
The claim that criminals are hijacking other people's AI accounts and servers to exploit LLMs holds up against the available evidence, with some details about scale and frequency still uncertain — making it Mostly True.
Verdict: Mostly True