← Back to Briefing
New 'LLMjacking' Attack Leverages Leaked AWS Credentials to Exploit Paid AI Models, Causing Significant Financial Loss
Importance: 92/1004 Sources
Why It Matters
This incident demonstrates a new vector for cyberattacks targeting AI infrastructure, emphasizing the urgent need for robust cloud security practices, credential management, and monitoring to prevent significant financial losses and unauthorized AI model usage.
Key Intelligence
- ■Hackers used leaked AWS Identity and Access Management (IAM) keys and API keys to hijack cloud accounts.
- ■The attackers exploited compromised AWS accounts to run expensive, paid AI models, specifically targeting Amazon Bedrock.
- ■One incident resulted in an estimated $600,000 in AI credits being burned by hackers.
- ■The attack highlights the critical vulnerability posed by leaked cloud credentials and API keys in accessing and abusing AI infrastructure.
Source Coverage
Google News - AI & LLM
9/4/2026Hackers Hijack AWS Account to Run Paid AI Models in LLMjacking Attack - Hackread
Google News - Dev Tools
9/4/2026Hackers Steal Metr API Key, Burn $600K in AI Credits - BankInfoSecurity
Google News - AI & LLM
9/3/2026LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access - CyberSecurityNews
Google News - AI & LLM
9/4/2026