Cybercriminals are shifting tactics away from traditional ransomware and data exfiltration to target enterprise artificial intelligence infrastructure, stealing corporate API keys and login credentials to run up massive cloud bills. According to cybersecurity research firm CrowdStrike in its 2026 Threat Hunting Report, malicious actors are increasingly engaging in LLMJacking and Cost Harvesting—two emerging cyberattack methodologies where attackers hijack access to large language models and generate thousands of automated requests per minute.
In one severe incident highlighted in the report, hackers initiated nearly two hundred thousand API calls within a two-minute window using compromised enterprise credentials, forcing the victimized company to pay exorbitant usage fees for computational resources consumed by unauthorized third parties. The economic threat stems from the rapid integration of generative artificial intelligence across enterprise operations like automated coding, customer service bots, and predictive analytics.
Unlike legacy ransomware attacks that encrypt critical databases or threaten public data leaks, LLMJacking operates silently by exploiting authentic enterprise access tokens without disrupting regular business functions. Attackers siphon stolen compute capacity to power their own commercial AI services, run automated web scraping routines, or resell access on gray-market cybercrime forums. Meanwhile, Cost Harvesting attacks are launched specifically to inflict severe financial damage on target organizations by deliberately exhausting monthly cloud budgets and API rate limits.
Cybersecurity experts warn that traditional perimeter defenses and static IP blocking are failing to detect these attacks because the unauthorized requests use legitimate authentication credentials. As enterprise deployment of cloud-hosted language models accelerates worldwide, security analysts advise organizations to implement strict access controls, mandatory multi-factor authentication for API token generation, real-time rate limiting, and anomaly detection systems that track sudden spikes in automated inference traffic. Without proactive credential governance and continuous usage monitoring, companies risk severe financial losses as threat actors continue weaponizing corporate compute resources for profit.

