# llmjacking

Source: https://startwithidentity.com/glossary/llmjacking/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

LLMjacking is the use of stolen credentials to consume, resell, or abuse someone else's access to a large language model, usually through a cloud account or an AI provider API key, leaving the victim with the bill. The term was coined by the Sysdig Threat Research Team in 2024.

In the cases Sysdig documented, attackers obtained cloud access keys, found hosted model services such as Amazon Bedrock, invoked models directly, and in some cases sold access onward through reverse proxies; Sysdig estimated costs to a victim of more than 46,000 dollars a day for some models, and two to three times that for the most expensive. The same pattern now extends to AI provider keys and sessions harvested by infostealers, such as the [live API keys for four AI providers](https://startwithidentity.com/blog/2026-09-09-okta-finds-replayable-ai-session-tokens-in-infostealer-logs/) Okta found in one dump. Defenses are ordinary credential hygiene applied to a new, expensive target: no long-lived AI keys in code or on laptops, least-privilege policies that deny model invocation to identities that do not need it, budget alerts, and model invocation logging, including alerts on attempts to switch that logging off.

See also: [API key](https://startwithidentity.com/glossary/api-key/), [infostealer](https://startwithidentity.com/glossary/infostealer/), [static API key abuse](https://startwithidentity.com/techniques/static-api-key-abuse/), [secrets management](https://startwithidentity.com/glossary/secrets-management/)
