Google has flagged a growing cybercrime trend it calls LLM-jacking, in which attackers steal cloud credentials or API keys and use the victim’s paid computing power to run AI models and automated agents, leaving the account owner to settle the bill. 

The name borrows from cryptojacking, the older scheme where criminals hijacked other people’s servers to mine cryptocurrency; only now the prize is the scarce and costly GPUs that AI workloads depend on.

It usually begins with a slip, such as a personal access token accidentally committed to GitHub, a leaked API key, or a session token lifted by malware. 

Once the attacker holds the credential, they log into the victim’s cloud account, switch on GPU-heavy virtual machines and AI services, and start running their models, coding tools, or attack infrastructure.

The owner tends to find out when the invoice arrives and sometimes through degraded services, stolen data, or a suspended account.

Google described an incident investigated by its Mandiant team in which an attacker used an exposed personal access token to deploy unauthorized AI infrastructure and scale up high-performance computing, with the customer left responsible for the costs.

Free compute is a part of the appeal of what hackers want. Stolen infrastructure lets criminals run or fine-tune models without paying for GPUs, operate AI agents for phishing, credential theft, and vulnerability scanning, and resell access to hijacked AI accounts, all while keeping the activity away from their systems.

Proprietary prompts, models, source code, and training data can also be within reach once they are inside.

Surprise charges are the visible damage, though the deeper worry is that a compromised account becomes a foothold for lateral movement into other systems, data theft, and automated attacks on other organizations. 

Google says it watches for sudden VM creation, abnormal resource use, suspicious API activity, and unusual access contexts, and may throttle malicious traffic or isolate the affected resource when it spots them.

For anyone with a billable account on Google Cloud, AWS, Azure, or an AI API, the advice is mostly basic hygiene, applied consistently.

Keep keys and tokens out of public repositories, rotate them at once if they may have leaked, and prefer short-lived credentials with least-privilege permissions. 

Turning on MFA for administrator accounts, setting billing budgets, anomaly alerts, and GPU quota limits, and reviewing audit logs for new VMs, changed permissions, unfamiliar regions, and unexpected AI usage all narrow the window an attacker has. 

Keeping development, testing, and production in separate accounts also limits how far a single stolen key can travel.

People who only use a consumer AI app face a different exposure, mainly account theft and prompt privacy, rather than someone quietly taking over a GPU cluster.

The cloud version of the problem falls on developers, startups, and enterprises, along with anyone holding API credentials tied to a bill.