← the record
WF-DHFRU5

Alleged LLMjacking Targets AI Cloud Services with Stolen Credentials

Attackers reportedly exploited stolen cloud credentials obtained through a vulnerable Laravel system (CVE-2021-3129) to allegedly abuse AI cloud services, including Anthropic’s Claude and AWS Bedrock, in a scheme referred to as “LLMjacking.” The attackers are said to have monetized access through reverse proxies, reportedly inflating victim costs to as much as $100,000 per day. Additionally, they allegedly bypassed sanctions, enabled LLM models, and evolved techniques to evade detection and logging.

Date it happened
2024-05-06
Organisation involved
LLMjacking Attackers Exploiting Laravel, Entities engaging in Russian sanctions evasion
Product, system or model
OpenRouter services, OpenAI models, Mistral-hosted models, MakerSuite tools, GCP Vertex AI models, ElevenLabs services, Azure-hosted LLMs, AWS Bedrock-hosted models, Anthropic Claude (v2/v3), AI21 Lab
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.