A Cloud Security Alliance research note describes LLMjacking as the unauthorized use of cloud-hosted large language model resources through stolen credentials, exposed APIs or unauthenticated endpoints. It says the threat evolved from the proof-of-concept activity documented by Sysdig in 2024 into a commercially structured criminal market by early 2026. The note examines Operation Bizarre Bazaar, a campaign reported by Sysdig and Pillar Security Research that captured 35,000 attack sessions against honeypots between December 2025 and January 2026, or an average of 972 attacks per day. Its three-stage supply chain uses Shodan and Censys for reconnaissance, tests endpoints and model quality for economic value, and resells access through the silver.inc marketplace. The marketplace allegedly offers unauthorized access to more than 30 LLM providers at discounts of 40% to 60%, using Telegram and Discord and accepting cryptocurrency and PayPal. The report attributes the operation to an actor using the aliases Hecker, Sakuya and LiveGamer101, based on linked domains, infrastructure and an identifying message in an administrative panel. It cites estimates of potential AWS Bedrock losses exceeding $46,000 per day under maximum quota consumption, while a higher estimate above $100,000 per day for frontier models is described as commercially produced and not independently confirmed. A separate campaign targeting Model Context Protocol endpoints generated 60% of late-January honeypot traffic, although its intent remains uncertain; exposed MCP servers can provide access to files, databases, shells and internal APIs. The note also says attackers targeted DeepSeek-V3 shortly after release, exploiting gaps in monitoring and billing baselines for newly enabled models. Its recommendations include auditing active models and permissions, replacing long-lived keys with short-lived credentials, enabling invocation logs and AI-specific billing alerts, restricting self-hosted inference servers and MCP endpoints to authenticated internal access, and monitoring reconnaissance and validation behavior. It maps these controls to CSA frameworks including MAESTRO, the Cloud Controls Matrix and the LLM Threats Taxonomy.
AI News
The latest AI releases, research, products, and industry updates.
Loading...