The illegal acquisition of AI models and computing power has become a new hotspot in the cybercrime black market, with a significant increase in large language model (LLM) hijacking incidents this year. Criminal activities include selling stolen accounts for publicly available AI tools and misappropriating others' computing power to run proprietary models. The underground market has established a trading system centered around AI access rights, with significant discounts on access to AI models from companies like Anthropic, Google, and OpenAI available on the dark web. Some sellers even offer services to replace credentials for free if an account is banned. Additionally, criminal groups and state-sponsored organizations are infiltrating corporate cloud servers to implant their own AI models and misappropriate computing power. As large enterprises deploy custom AI models on their own servers, these self-running AI systems also face the risk of being attacked. Currently, as companies navigate the process of determining AI computing power usage, hackers may exploit the fact that increases in computing power usage can be easily overlooked to infiltrate systems and gain a cost advantage.
