AI Access Becomes New Commodity for Cybercriminals


Illegal access to artificial intelligence models has reportedly become a key commodity for cybercriminals.

That’s according to a report Sunday (Sept. 27) by the Financial Times (FT), which said this trend is happening as hackers look to employ expensive large language models (LLMs) for extortion, warfare and espionage.

John Hultquist, chief analyst for Google Threat Intelligence Group, told the FT the company has seen a major increase in so-called LLM-jacking this year, such as the sale of pilfered login credentials for public AI tools and the theft of computing resources by groups looking to run their own models for free.

“What we are seeing in the underground is a growing economy associated with access to AI,” said Hultquist, warning that low-cost access to expensive AI gives cyber attackers a financial advantage over their targets, who need to defend themselves using the same AI tools.

“The bottom line is all this behaviour gives them a sort of economic or efficiency advantage against us, because they’re going to essentially be able to get their hands on these tokens at a much cheaper rate,” he said.

We’d love to be your preferred source for news.

Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

Dark web marketplaces are selling access to AI models from companies like Anthropic, OpenAI and Google at discounts of up to 97%, the report said, citing information from Google Threat’s researchers. AI subscriptions for the most advanced versions of OpenAI’s ChatGPT and Anthropic’s Claude can cost as much as $200 per user each month.

AI is now being used by “every threat actor,” Hultquist told FT, adding that AI tools will thus need to be central to the future of cybersecurity.

“Anybody who decides that AI is a fad and wants to let it just wash over them is going to wake up one day underwater,” he said. “They’re going to have more incidents, more alerts, more attacks than they’ve ever seen before. We have to get our house in order now.”

Meanwhile, recent research from PYMNTS Intelligence shows that companies are increasingly using AI to fend off cybercriminals, even as those criminals use the same technology.

According to “Prevention First: Building a Smarter Defense Against Payments Fraud,” 42% of companies said they use three or more AI defense tools as part of a layered stack.

At the same time, 50% of companies surveyed pointed to AI-generated vendor impersonation emails as their number one threat.

“Catching these fraud attempts is hard work, costing firms time and money,” the report said, adding that close to 90% of finance leaders “call verifying vendors a moderate or major burden.”

For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *