LLMjacking Leverages Leaked AWS IAM Access Key to Steal Paid Access to AI Models

A new attack method called “LLMjacking” has enabled attackers to use a leaked AWS credential to hijack paid access to AI models, create new users inside accounts and subscribe to models in the AWS Marketplace.

More details here: https://www.fortinet.com/blog/threat-research/someone-else-is-using-your-ai

Dan Moore, Sr. Director CIAM Strategy at cybersecurity company FusionAuth, provided the following comments:

“Abusing cloud accounts to resell access to premium AI models has graduated from an opportunistic hobby to a real business. Last month it was Poison Claude reselling fraudulently obtained access to Anthropic’s latest models on the cheap. This month it’s attackers using leaked AWS IAM keys to spin up new AWS accounts and running up Bedrock charges that researchers report can cost victims $100K/day.

AI doesn’t remove the need for security best practices. Use short-lived credentials rather than long-lived static API keys, force regular key rotation if long-lived credentials must be used, and enforce least privilege in both situations. Beyond that, set up alerting for budget overruns, privileged account creation or high resource consumption.”

People need to recognize that AI without safeguards means risk for organizations. Therefore you need to make sure that all and any safeguards are in place before deploying AI.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading