{"id":26319,"date":"2026-09-19T15:41:14","date_gmt":"2026-09-19T15:41:14","guid":{"rendered":"https:\/\/koshalsambada.in\/?p=26319"},"modified":"2026-09-19T15:41:14","modified_gmt":"2026-09-19T15:41:14","slug":"hackers-arent-just-stealing-data-anymore-theyre-stealing-your-ai-access","status":"publish","type":"post","link":"https:\/\/koshalsambada.in\/?p=26319","title":{"rendered":"Hackers aren\u2019t just stealing data anymore, they\u2019re stealing your AI access"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-134355622,imgsize-101504,width-400,height-225,resizemode-4\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg\" alt=\"Hackers aren\u2019t just stealing data anymore, they\u2019re stealing your AI access\" title=\"AI theft economy\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>It sounds absurd: someone breaks into your system, and instead of emptying your database, they start making you pay for their AI.<span class=\"id-r-component br\" data-pos=\"1\"\/>But that is increasingly the point.<span class=\"id-r-component br\" data-pos=\"3\"\/>A stolen AI credential can give an attacker more than access to a company. <!-- -->It can give them computing power that the company has already paid for.<span class=\"id-r-component br\" data-pos=\"7\"\/>Attackers are increasingly stealing API keys, login sessions and other credentials that provide access to AI services, using them to run their own workloads, resell the access or hide behind legitimate customer accounts. The target is no longer necessarily the data sitting inside an organisation. In some cases, it is the AI access itself.<span class=\"id-r-component br\" data-pos=\"9\"\/>Anthropic\u2019s September 2026 threat report describes an emerging criminal economy built around stolen AI access. <!-- -->Attackers are harvesting credentials from code repositories, mobile applications, websites, Docker containers, chatbots and other places where companies accidentally expose them. Those credentials can then be resold, used in further attacks, or simply used to run AI workloads at the legitimate customer\u2019s expense.<span class=\"id-r-component br\" data-pos=\"14\"\/>The economics are simple: one stolen key can deliver three things &#8211; loot, compute and cover.<span class=\"id-r-component br\" data-pos=\"16\"\/><\/p>\n<div class=\"cdatainfo   id-r-component \" data-pos=\"17\">\n<ul>\n<li>Loot &#8211; because <keyword id=\"39429397\" type=\"Denny\" weightage=\"20\" keywordseo=\"stolen-AI-credentials\" source=\"keywords\">stolen AI credentials<\/keyword> can be resold.<\/li>\n<li>Compute &#8211; because someone else can foot the bill for the workload.<\/li>\n<li>Cover &#8211; because the activity can look like it is coming from a legitimate customer.<\/li>\n<\/ul>\n<\/div>\n<p>CrowdStrike&#8217;s 2026 Threat Hunting Report has observed a similar shift. In one campaign, attackers abusing corporate AI access generated nearly 200,000 API requests in an initial two-minute flood, using the victim&#8217;s AI resources rather than simply stealing information from the account.<span class=\"id-r-component br\" data-pos=\"21\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"The new AI theft economy\" msid=\"134355645\" imgsize=\"367428\" resizemode=\"4\" width=\"\" title=\"A stolen AI key can give attackers more than access \u2014 it can give them computing power.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-367428,msid-134355645\/the-new-ai-theft-economy.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p>A stolen AI key can give attackers more than access \u2014 it can give them computing power.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"23\"\/><\/p>\n<p><h3>AI access is becoming something criminals can sell<\/h3>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"25\"\/>An API key is a string of characters that works like a digital pass. It allows an application to use an online service without a person having to log in each time. When linked to an AI service, that key can allow software to send requests to an AI model.<span class=\"id-r-component br\" data-pos=\"28\"\/>A session token serves a similar purpose. It is a digital proof that a user has already logged in and can allow continued access to an account.<span class=\"id-r-component br\" data-pos=\"30\"\/>If criminals steal either, they may not need the victim&#8217;s password. They may be able to use the existing access instead.<span class=\"id-r-component br\" data-pos=\"32\"\/>Anand Venkatraman, Partner, Deloitte India, said this represents a change in how stolen credentials are viewed.<span class=\"id-r-component br\" data-pos=\"34\"\/>\u201cAPI keys and session tokens have emerged as a new class of high-value digital assets. <!-- -->Historically, stolen credentials were a means to access networks, applications, or data. Today, the credential itself is often the target.\u201d<span class=\"id-r-component br\" data-pos=\"38\"\/>The reason is simple. A working AI credential can already have an economic value.<span class=\"id-r-component br\" data-pos=\"40\"\/>\u201cA live API key linked to a funded enterprise AI account is a monetizable asset that can be resold or abused directly, much like cloud credentials became valuable commodities once cloud compute gained economic value,\u201d Venkatraman said.<span class=\"id-r-component br\" data-pos=\"43\"\/>In other words, criminals do not necessarily need to steal what an AI service has generated. They can steal the ability to use the service in the first place.<span class=\"id-r-component br\" data-pos=\"45\"\/>Anthropic says one hacktivist campaign ran for an entire month using stolen API keys. In another case, suspected ShinyHunters affiliates stole AI keys during an intrusion and switched their own attack workloads onto those keys.<span class=\"id-r-component br\" data-pos=\"47\"\/>The theft is also becoming industrialised.<span class=\"id-r-component br\" data-pos=\"50\"\/>One criminal pipeline downloaded 1.8 million Android APKs, decompiled them and searched them for hardcoded secrets. A separate harvesting operation collected GitHub personal access tokens. The stolen credentials were then validated and fed into criminal operations.<span class=\"id-r-component br\" data-pos=\"52\"\/>Another group went after users themselves by pretending to sell cheap access to frontier AI models. Victims who installed what appeared to be AI software instead handed over credentials and authenticated session tokens. <!-- -->The stolen access was then sold onward to other AI resellers.<span class=\"id-r-component br\" data-pos=\"56\"\/>And the target is not limited to ordinary AI users.<span class=\"id-r-component br\" data-pos=\"58\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"The new AI theft economy\" msid=\"134355681\" imgsize=\"398942\" resizemode=\"4\" width=\"\" title=\"From exposed keys to underground brokers, stolen AI access can pass through several hands.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-398942,msid-134355681\/the-new-ai-theft-economy.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p>From exposed keys to underground brokers, stolen AI access can pass through several hands.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"60\"\/><\/p>\n<p><h3>Criminals can make the victim pay for their AI use<\/h3>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"62\"\/>AI services are generally paid for based on usage. The more a customer uses a model, the more computing resources are consumed and, depending on the service, the larger the bill can become.<span class=\"id-r-component br\" data-pos=\"64\"\/>This creates an opportunity for attackers.<span class=\"id-r-component br\" data-pos=\"66\"\/>They can take a stolen credential and use the victim&#8217;s account to run their own AI workloads. <!-- -->This is sometimes referred to as LLMJacking, where criminals hijack access to an AI model and use the victim&#8217;s computing resources.<span class=\"id-r-component br\" data-pos=\"70\"\/>CrowdStrike said it observed financially motivated criminals abusing corporate large language model, or LLM, access for LLMJacking and cost harvesting. In one campaign, attackers sent nearly 200,000 API requests in an initial two-minute flood.<span class=\"id-r-component br\" data-pos=\"72\"\/>CrowdStrike describes cloud resource hijacking as the unauthorised use of a victim&#8217;s computing resources after an account is compromised. <!-- -->The same approach can be used for cryptocurrency mining or AI workloads, with the victim effectively providing the computing power and paying the associated cost.<span class=\"id-r-component br\" data-pos=\"76\"\/>Venkatraman said the economics are similar to earlier forms of cybercrime.<span class=\"id-r-component br\" data-pos=\"78\"\/>\u201cThe move from data theft to access theft reflects a natural evolution of cybercrime. Underground markets have progressed from selling VPN and RDP access to cloud credentials, and now AI platform access.\u201d<span class=\"id-r-component br\" data-pos=\"81\"\/>The attraction is that a stolen AI account may already have a payment method, an established usage history and access to models that could otherwise be expensive to use.<span class=\"id-r-component br\" data-pos=\"83\"\/><\/p>\n<p><h3>A legitimate account can also provide cover<\/h3>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"85\"\/>There is another advantage for criminals. Activity carried out using a legitimate customer&#8217;s account can be harder to distinguish from normal usage.<span class=\"id-r-component br\" data-pos=\"87\"\/>\u201cA stolen AI credential isn&#8217;t just reusable, it&#8217;s a paid-for gateway: the attacker inherits legitimate compute quota and model access under someone else&#8217;s billing and identity, making the activity far harder to flag than a conventional stolen password,\u201d said Saurabh Sharma, security researcher, Global Research and Analysis Team (GReAT), Kaspersky.<span class=\"id-r-component br\" data-pos=\"90\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"The new AI theft economy\" msid=\"134355685\" imgsize=\"305108\" resizemode=\"4\" width=\"\" title=\"Hackers are increasingly treating AI credentials as digital assets that can be harvested and resold.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-305108,msid-134355685\/the-new-ai-theft-economy.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p>Hackers are increasingly treating AI credentials as digital assets that can be harvested and resold.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"92\"\/>Venkatraman identified three reasons stolen AI credentials are attractive: they can be resold, they provide access to paid computing resources and they allow criminals to operate through a legitimate customer&#8217;s account.<span class=\"id-r-component br\" data-pos=\"94\"\/>This means an attacker does not always have to create a new account or find a way to pay for AI services. The victim&#8217;s existing access can do that work.<span class=\"id-r-component br\" data-pos=\"96\"\/><\/p>\n<p><h3>Developers are leaving credentials in places criminals can search<\/h3>\n<\/p>\n<p>The growing value of AI credentials is also changing what criminals look for when searching the internet.<span class=\"id-r-component br\" data-pos=\"101\"\/>Anthropic said attackers have been searching public code repositories, mobile applications, container images and websites for API keys and session tokens. In one case documented by the company, an attacker stole AI API keys from an enterprise software vendor and subsequently used one of those keys for secondary attacks against other organisations.<span class=\"id-r-component br\" data-pos=\"103\"\/>The problem often starts with something as straightforward as a developer accidentally leaving a key inside software code.<span class=\"id-r-component br\" data-pos=\"106\"\/>Venkatraman said common sources include \u201cHardcoded keys committed to repositories and exposed through forks or misconfigured CI\/CD pipelines\u201d, credentials embedded inside mobile applications, secrets included in container images and tokens exposed through client-side JavaScript.<span class=\"id-r-component br\" data-pos=\"108\"\/>A container image is essentially a packaged version of software that can be moved between computers or cloud services. If a secret is accidentally included in that package, anyone who obtains it may also obtain the credential.<span class=\"id-r-component br\" data-pos=\"111\"\/>Kaspersky has seen similar activity in developer tools. Sharma cited the 2025 singularity incident, in which attackers stole a package-publishing token and used it to push malicious npm packages designed to steal secrets from Claude Code, Gemini CLI and Amazon Q CLI.<span class=\"id-r-component br\" data-pos=\"113\"\/><\/p>\n<div data-pos=\"0\" class=\"id-r-component iIpbx undefined  &#10;        \">\n<div><img decoding=\"async\" alt=\"The new AI theft economy\" msid=\"134355691\" imgsize=\"398942\" resizemode=\"4\" width=\"\" title=\"AI access is becoming a new target as attackers seek keys, accounts, compute and billing access.\" placeholdersrc=\"https:\/\/static.toiimg.com\/photo\/83033472.cms\" offsetvertical=\"0\" placeholdermsid=\"47529300\" type=\"thumb\" class=\"\" src=\"https:\/\/static.toiimg.com\/photo\/imgsize-398942,msid-134355691\/the-new-ai-theft-economy.jpg\" data-api-prerender=\"true\"\/><\/p>\n<p>AI access is becoming a new target as attackers seek keys, accounts, compute and billing access.<\/p>\n<\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"115\"\/>CrowdStrike also found attackers targeting software development environments, package registries and container registries. It said npm accounted for 87% of malicious software registry threats in the first half of 2026.<span class=\"id-r-component br\" data-pos=\"118\"\/><\/p>\n<p><h3>AI is adding more links to the supply chain<\/h3>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"120\"\/>The term AI supply chain can sound abstract, but the idea is relatively simple. Companies increasingly connect AI services to their software, customer support systems, internal databases and automated assistants. Each connection needs some form of permission or credential.<span class=\"id-r-component br\" data-pos=\"122\"\/>That creates more places where access can be exposed or stolen.<span class=\"id-r-component br\" data-pos=\"124\"\/>AI agents are making this network wider. An AI agent is software that can carry out tasks on behalf of a user, rather than simply responding to a question. <!-- -->Such agents can be connected to email, messaging, calendars, company databases and other services.<span class=\"id-r-component br\" data-pos=\"128\"\/>Sharma said this is creating more potential routes into an organisation.<span class=\"id-r-component br\" data-pos=\"130\"\/>\u201cAbsolutely every new integration point is a new credential to protect. We&#8217;ve flagged that AI agents are frequently connected to email, messaging, task-management systems, knowledge bases and MCP servers, meaning a malicious instruction or a credential leak can now originate from virtually any source the agent processes automatically.\u201d<span class=\"id-r-component br\" data-pos=\"133\"\/>For companies, that means protecting an AI system is no longer only about securing the model itself. The credentials that connect the model to other services can become targets too.<span class=\"id-r-component br\" data-pos=\"135\"\/>Venkatraman said this is particularly relevant for Indian enterprises because AI deployments can also create new compliance responsibilities.<span class=\"id-r-component br\" data-pos=\"138\"\/>\u201cThis trend resembles the evolution from &#8220;shadow IT&#8221; to &#8220;shadow cloud&#8221; and now &#8220;shadow AI.&#8221; <!-- -->For Indian enterprises, governance challenges are amplified by requirements such as RBI outsourcing guidelines, CERT-In incident reporting obligations, and the DPDP framework.\u201d<span class=\"id-r-component br\" data-pos=\"142\"\/>He said organisations should treat AI credentials with the same level of care as other privileged access, including limiting what each credential can do, regularly replacing credentials, monitoring their use and including them in incident response plans.<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/hackers-arent-just-stealing-data-anymore-theyre-stealing-your-ai-access\/articleshow\/134355500.cms\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It sounds absurd: someone breaks into your system, and instead of emptying your database, they start making you pay for their AI.But that is increasingly the point.A stolen AI credential can give an attacker more than access to a company. It can give them computing power that the company has already paid for.Attackers are increasingly [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":26320,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-26319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-31"],"magazineBlocksPostFeaturedMedia":{"thumbnail":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","medium_large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","1536x1536":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","2048x2048":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-small":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-small-tall":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-small-square":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-small-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-medium-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg","blogsy-wide":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg"},"magazineBlocksPostAuthor":{"name":"admin","avatar":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g"},"magazineBlocksPostCommentsNumber":"0","magazineBlocksPostExcerpt":"It sounds absurd: someone breaks into your system, and instead of emptying your database, they start making you pay for their AI.But that is increasingly the point.A stolen AI credential can give an attacker more than access to a company. It can give them computing power that the company has already paid for.Attackers are increasingly [&hellip;]","magazineBlocksPostCategories":["\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36"],"magazineBlocksPostViewCount":1,"magazineBlocksPostReadTime":8,"magazine_blocks_featured_image_url":{"full":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg",400,225,false],"medium":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg",300,169,false],"thumbnail":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/09\/the-new-ai-theft-economy-is-turning-stolen-access-into-a-source-of-money-compute-and-cover.jpg",150,84,false]},"magazine_blocks_author":{"display_name":"admin","author_link":"https:\/\/koshalsambada.in\/author\/admin"},"magazine_blocks_comment":0,"magazine_blocks_author_image":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g","magazine_blocks_category":"<a href=\"#\" class=\"category-link category-link-31\">\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36<\/a>","_links":{"self":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/26319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26319"}],"version-history":[{"count":0,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/26319\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/media\/26320"}],"wp:attachment":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}