Hackers Illegally Access and Exploit AI Accounts for Costly Model Usage

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Hackers are increasingly stealing access to AI accounts and servers, using them to run expensive AI models without authorization. This illicit use, identified by Google researchers, results in significant financial losses for companies as stolen access is sold cheaply on the dark web. Major AI providers like OpenAI, Anthropic, and Google are affected.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the misuse of AI systems (large AI models and cloud computing resources) by hackers who steal access credentials or infiltrate servers to run AI models illicitly. This misuse directly causes harm by imposing financial costs on companies and represents a breach of security. The AI systems are central to the incident as their unauthorized use is the mechanism of harm. Therefore, this qualifies as an AI Incident due to realized harm caused by the development and use (misuse) of AI systems.[AI generated]
AI principles
Robustness & digital security

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Business

Harm types
Economic/Property

Business function:
Other

AI system task:
Content generation


Articles about this incident or hazard