Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials
Attackers reportedly exploited stolen cloud credentials obtained through a vulnerable Laravel system (CVE-2021-3129) to allegedly abuse AI cloud services, including Anthropic’s Claude and AWS Bedrock, in a scheme referred to as “LLMjacking.” The attackers are said to have monetized access through reverse proxies, reportedly inflating victim costs to as much as $100,000 per day. Additionally, they allegedly bypassed sanctions, enabled LLM models, and evolved techniques to evade detection and logging.
- Date it happened
- 2024-05-06
- Organisation involved
- LLMjacking Attackers Exploiting Laravel, Entities engaging in Russian sanctions evasion
- Product, system or model
- OpenRouter services, OpenAI models, Mistral-hosted models, MakerSuite tools, GCP Vertex AI models, ElevenLabs services, Azure-hosted LLMs, AWS Bedrock-hosted models, Anthropic Claude (v2/v3), AI21 Lab
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.