Published by GLCTech Sec, the UK monitoring, endpoint security and backup partner for regulated SMEs.
AI credential theft is one of the fastest-growing cyber threats of 2026. New research from Google, Okta, and Anthropic shows criminals are going after more than just your data. They are stealing API keys, login sessions, and cloud accounts behind the AI tools your business uses, then running up bills, reselling access, or using it for extortion. This guide explains what is happening, why UK accountancy, legal and financial firms should pay attention, and the practical steps that reduce the risk.
What is AI credential theft?
AI credential theft is the theft of anything that grants access to an AI service or the cloud infrastructure behind it. That includes:
- API keys used by software to call AI services;
- Session tokens, the browser cookies that keep you logged in to AI assistants and cloud portals;
- Cloud account credentials that can be used to switch on and consume AI services.
Google Threat Intelligence Group's AI Threat Tracker (8 September 2026) reports attackers stealing API credentials, targeting proprietary AI models and source code, and taking over victims' cloud environments to run unauthorised AI workloads.
What is LLMjacking?
LLMjacking is the term security researchers at Sysdig coined in 2024 for hijacking someone else's large language model (LLM) access. The attacker uses stolen credentials to run AI workloads, and the victim pays. In its original research, Sysdig estimated one attack could generate more than US$46,000 of AI usage costs per day.
The problem has grown since. Okta Threat Intelligence's September 2026 research describes one organisation facing a bill of nearly US$1 million, an individual software architect hit with a US$25,000 surprise bill, and an AI testing organisation losing US$600,000 in AI credits because of a stolen API key.
How are AI accounts being stolen?
1. Infostealer malware on staff devices
Infostealers are malware that quietly harvest saved passwords and browser session tokens from infected computers. Okta analysed a large dump of infostealer logs and found thousands of AI-platform session tokens. With a valid token, an attacker can replay your session and bypass both the password and multi-factor authentication.
2. Keys left in code, containers and shared files
Anthropic's September 2026 threat report describes attackers systematically searching public code repositories, container images, apps and websites for credentials and API keys. In one case, a single stolen developer token escalated to full administrative control of a victim's cloud environment in roughly three hours.
3. Buying access on underground markets
According to reporting on Google's findings, underground prices for stolen AI accounts, particularly Claude and Gemini accounts, more than doubled during 2026. Rising prices signal rising demand.
From stolen access to extortion
Stolen AI data is also being used for ransom. Google's Mandiant investigated several extortion cases in Q2 2026 in which attackers stole proprietary AI models, prompts, source code and research from technology, healthcare and media companies in North America and Europe, then threatened to publish the data unless the victim paid.
Regulators are now seeing AI-executed incidents too. In September 2026, Spain's data protection authority (AEPD) reported receiving its first breach notification in which the victim organisation said an AI agent logged in and autonomously found a flaw that let it modify personal data and access invoices. The AEPD stressed that the account comes from the victim's notification and is still under analysis.
Why UK accountancy, legal and financial firms should care
Most professional-services SMEs are not building their own AI models. Your realistic exposure is more everyday:
- a staff laptop infected with an infostealer, leaking sessions for email, cloud and AI tools;
- an API key for an AI-enabled product pasted into a script, spreadsheet or shared drive;
- an unnoticed spike in cloud or AI usage that only shows up on the invoice;
- client personal data processed through AI tools becoming reachable by an attacker.
If personal data is involved, UK GDPR still applies in full. Notifiable breaches must be reported to the ICO within 72 hours (see the ICO's breach reporting page). For firms that answer to clients, insurers and regulators, "it was an AI" is not a defence.
7 steps to protect your business from AI credential theft
- Harden every endpoint. Use managed endpoint protection that is actively monitored, because infostealers start on user devices.
- Remove secrets from code and files. Scan repositories and containers for exposed keys, and use a secrets manager instead of hard-coding credentials.
- Rotate exposed keys immediately. Treat any key that has appeared in a repo, ticket, email or chat as compromised.
- Set spending limits and billing alerts on every cloud and AI account, so a hijacked key triggers an alert rather than an invoice shock.
- Monitor for anomalies 24/7. Unusual traffic, logins and resource usage across servers, networks and applications are often the first sign of compromise.
- Keep immutable, tested backups. A reliable restore turns an extortion demand into a manageable incident.
- Govern your AI use. Know which AI tools staff use, what data goes into them and who holds the keys. Treat prompts and AI configurations as sensitive assets.
The NCSC's free guidance for small and medium-sized organisations is a strong baseline for all of the above.
How GLCTech Sec helps you stay ahead
GLCTech Sec helps UK regulated SMEs put these controls in place without building an in-house security team:
- Managed Endpoint Security: vendor-agnostic protection (Kaspersky, Microsoft Defender for Business, Bitdefender or Sophos) to cut off the infostealer infections that leak session tokens.
- 24/7 Zabbix Infrastructure Monitoring: real-time monitoring of servers, networks and applications with Grafana dashboards and email and WhatsApp alerts, so anomalies are caught early.
- Veeam Backup & Recovery: automated backups and fast recovery, so ransom and extortion demands lose their leverage.
We publish our own security posture openly on our Trust & Compliance page, including UK GDPR processing terms and our progress towards Cyber Essentials certification.
Book a free 30-minute Security Gap Assessment at glctechsec.com, or email contact@glctechsec.com.
Frequently asked questions
Can attackers get into my AI account without my password?
Yes. If malware steals a valid session token from your browser, an attacker can replay it and access the account without the password or MFA code. Okta's September 2026 research documents this happening at scale.
Who pays when a stolen API key is used?
Usually the account owner. Usage is billed to the account the key belongs to, which is why spending limits and billing alerts matter.
We don't build AI. Are we still at risk?
Yes. If your staff use AI assistants, AI-enabled software or cloud services, their sessions and keys are worth stealing. The most common route in is an infected endpoint, not a sophisticated attack on an AI model.
What is the quickest first step?
Find out where you stand. A short gap assessment covering endpoints, monitoring, backups and exposed credentials will show your biggest risks. GLCTech Sec offers one free.
Sources
- Google Threat Intelligence Group, GTIG AI Threat Tracker: From Prompting to Autonomy, 8 September 2026
- Okta Threat Intelligence (Jeremy Kirk), Signing in without actually signing in, 9 September 2026
- Anthropic, Detecting and countering misuse of AI: September 2026, 10 September 2026
- Sysdig Threat Research Team, LLMjacking: Stolen Cloud Credentials Used in New AI Attack, 6 May 2024
- AEPD, first breach notification attributed to an AI agent (Spanish), 14 September 2026
- AI Weekly, Google: underground AI account prices more than doubled in 2026
- NCSC, Cyber security advice for small to medium sized organisations
- ICO, Report a breach





