Wednesday, September 09, 2026

Sign In


Home USA Innovation Identity and Access Management LLMjacking Attack Exposes AWS ...

LLMjacking Attack Exposes AWS IAM Keys to Unauthorized AI Model Access


Identity and Access Management

LLMjacking Attack Exposes AWS IAM Keys to Unauthorized AI Model Access

A FortiGuard Labs investigation shows how attackers used a leaked AWS IAM key to access paid AI models, leaving victims with costly inference charges.

  • Attackers used a leaked AWS IAM key with AdministratorAccess privileges

  • A new IAM user was created to access paid AI models through AWS Marketplace

  • Unauthorized Amazon Bedrock usage can generate extremely high inference costs

  • LLMjacking allows attackers to monetize stolen AI access through online marketplaces and chat platforms

  • Security teams should prioritize short-lived credentials, CloudTrail and Bedrock logging

An example of LLMjacking recently discovered by FortiGuard Labs shows how a single leak of an AWS credential could give an attacker access to paid AI models while leaving the expenses on the victim’s account. It was established that the attack took advantage of an IAM access key with the AdministratorAccess permission, which had been leaked for quite some time. After the leak, the attacker managed to create a new IAM user in the compromised AWS account and use it to purchase foundation models from the AWS Marketplace through Amazon Bedrock.

This case demonstrates how IAM security in cloud environments is facing a new threat from attackers who can use valid credentials and legitimate services instead of utilizing obviously malicious tools. The problem with this attack is that it comes from an authorized user, making it harder for network protection systems to identify.

The potential cost of such attacks is also quite high. According to FortiGuard Labs, unauthorized usage of AI models like Claude 2.x may cost $46,000 per day, whereas usage of Claude 3 Opus may cost more than $100,000 per day. Stolen access to AI models is also being sold through platforms such as Telegram and Discord. Operation Bizarre Bazaar is another such operation that was involved in more than 35,000 attack sessions against over 30 LLM platforms.

FortiGuard Labs recommends activating AWS CloudTrail and Amazon Bedrock invocation logging to gain better visibility into identity creation, credential activity, and model usage. Where possible, organizations should use IAM credentials that expire quickly and use assumed roles instead. Business Honor observes that the attack highlights the growing importance of IAM security in cloud and AI environments. A single overprivileged credential can lead to serious security risks and unexpected AI costs.

Frequently Asked Questions

LLMjacking is a cyberattack in which criminals use stolen cloud credentials to access paid AI models and shift the usage costs to the victim.

The leaked IAM key had AdministratorAccess permissions, allowing the attacker to create a new IAM user and access paid AI models through AWS services.

Unauthorized usage can result in extremely high costs, with FortiGuard Labs reporting potential charges of more than $46,000 per day for Claude 2.x and over $100,000 per day for Claude 3 Opus.

Attackers can use valid credentials and legitimate cloud services, making their activity appear similar to authorized AI usage.

Organizations should enable AWS CloudTrail and Bedrock invocation logging, monitor unusual IAM activity, and use short-lived credentials and assumed roles where possible.


Comments

0 Comments

Business News


Recommended News

×

Subscribe To Our Newsletter

email

please enter valid email

×
tankyu


Latest Magazine