LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access
Brief
A newly documented cloud intrusion shows how quickly attackers can turn a single leaked AWS credential into a revenue stream by hijacking access to premium AI models, a technique researchers call LLMjacking.
Security researchers at FortiGuard Labs traced the incident to a long-lived AWS Identity and Access Management (IAM) access key carrying AdministratorAccess permissions, the highest level of privilege an AWS identity can hold.
Once in possession of this key, the attacker created a brand-new IAM user inside the victim’s account and used it to subscribe to foundation models available through AWS Marketplace, issuing CreateAgreementRequest and AcceptAgreementRequest calls against the marketplace’s agreement service.
With the subscription active, the attacker began invoking the models directly, generating inference charges billed entirely to the compromised organization.
