Dark web AI model sales surge: hackers leverage discounted access for cyber offensives
According to a Financial Times report from September 26, 2026, illegally obtained AI models and computing power are in high demand on the cybercrime black market. Hackers use these resources for ransomware, cyber warfare, and espionage. John Hultquist, chief analyst at Google's threat intelligence team, noted a significant rise in 'LLM hijacking' activities, with stolen login credentials for public AI tools and unauthorized use of computing power for free model training. Hultquist highlighted an underground economic system around AI usage, with access to models from Anthropic, Google, and OpenAI being sold on the dark web at discounts up to 97%. In contrast, the highest subscription for ChatGPT and Claude can cost up to $200 per user per month. Some sellers offer 'guaranteed access' services, promising free credentials if initial accounts are banned.
Hultquist warned that attackers are leveraging low-cost AI access to gain an economic or efficiency advantage over their targets. He noted that criminal groups and state-sponsored entities are infiltrating enterprise servers to run their own AI models, similar to cryptocurrency mining. With more companies deploying custom AI models on their own servers, Hultquist stressed the need for heightened protection, as this computing power will become a key target for threat actors. He emphasized that the current surge in AI adoption creates an opportunity for hackers to infiltrate systems, as increased computing power usage may be mistaken for normal activity.