AI NEWS 24
Qualcomm Secures $60 Billion AI Chip Deal with Amazon 95GPT-6 Achieves Landmark Breakthrough in AI Antibody Prediction 94Anthropic Reports Blocking AI Misuse for Bioweapons, Cyberattacks, and Espionage 93OpenAI Explores Slowing AI Development, Citing Legal and Coordination Hurdles 93AI's Soaring Power Demand Reshaping Data Center Infrastructure 93AI Competition Shifts from Model Development to Infrastructure Dominance 93DeepSeek Launches Advanced AI Model Amid Escalating 'Distillation' Accusations from Western Rivals 92US Accuses Chinese Firms of Industrial-Scale AI Theft Amidst Calls for Dialogue 92US-China AI Competition Intensifies Amid Data Security Concerns and Dialogue Calls 92TSMC Achieves Record Revenue Amid Surging AI Chip Demand, Bank of Korea Warns on Chipmaker Derivatives 92///Qualcomm Secures $60 Billion AI Chip Deal with Amazon 95GPT-6 Achieves Landmark Breakthrough in AI Antibody Prediction 94Anthropic Reports Blocking AI Misuse for Bioweapons, Cyberattacks, and Espionage 93OpenAI Explores Slowing AI Development, Citing Legal and Coordination Hurdles 93AI's Soaring Power Demand Reshaping Data Center Infrastructure 93AI Competition Shifts from Model Development to Infrastructure Dominance 93DeepSeek Launches Advanced AI Model Amid Escalating 'Distillation' Accusations from Western Rivals 92US Accuses Chinese Firms of Industrial-Scale AI Theft Amidst Calls for Dialogue 92US-China AI Competition Intensifies Amid Data Security Concerns and Dialogue Calls 92TSMC Achieves Record Revenue Amid Surging AI Chip Demand, Bank of Korea Warns on Chipmaker Derivatives 92
← Back to Briefing

New 'LLMjacking' Attack Leverages Leaked AWS Credentials to Exploit Paid AI Models, Causing Significant Financial Loss

Importance: 92/1004 Sources

Why It Matters

This incident demonstrates a new vector for cyberattacks targeting AI infrastructure, emphasizing the urgent need for robust cloud security practices, credential management, and monitoring to prevent significant financial losses and unauthorized AI model usage.

Key Intelligence

  • Hackers used leaked AWS Identity and Access Management (IAM) keys and API keys to hijack cloud accounts.
  • The attackers exploited compromised AWS accounts to run expensive, paid AI models, specifically targeting Amazon Bedrock.
  • One incident resulted in an estimated $600,000 in AI credits being burned by hackers.
  • The attack highlights the critical vulnerability posed by leaked cloud credentials and API keys in accessing and abusing AI infrastructure.