A FortiGuard Labs investigation shows how attackers used a leaked AWS IAM key to access paid AI models, leaving victims with costly inference charges.
|
An example of LLMjacking recently discovered by FortiGuard Labs shows how a single leak of an AWS credential could give an attacker access to paid AI models while leaving the expenses on the victim’s account. It was established that the attack took advantage of an IAM access key with the AdministratorAccess permission, which had been leaked for quite some time. After the leak, the attacker managed to create a new IAM user in the compromised AWS account and use it to purchase foundation models from the AWS Marketplace through Amazon Bedrock.
This case demonstrates how IAM security in cloud environments is facing a new threat from attackers who can use valid credentials and legitimate services instead of utilizing obviously malicious tools. The problem with this attack is that it comes from an authorized user, making it harder for network protection systems to identify.
The potential cost of such attacks is also quite high. According to FortiGuard Labs, unauthorized usage of AI models like Claude 2.x may cost $46,000 per day, whereas usage of Claude 3 Opus may cost more than $100,000 per day. Stolen access to AI models is also being sold through platforms such as Telegram and Discord. Operation Bizarre Bazaar is another such operation that was involved in more than 35,000 attack sessions against over 30 LLM platforms.
FortiGuard Labs recommends activating AWS CloudTrail and Amazon Bedrock invocation logging to gain better visibility into identity creation, credential activity, and model usage. Where possible, organizations should use IAM credentials that expire quickly and use assumed roles instead. Business Honor observes that the attack highlights the growing importance of IAM security in cloud and AI environments. A single overprivileged credential can lead to serious security risks and unexpected AI costs.




























.webp)
Comments
0 Comments