Program report QB-7699 · filed September 28, 2026
AI in SalesMeasured report
Stolen AI Accounts Are Now a Fast-Growing Dark Web Market
Chosunbiz reports dark web sales of stolen AI accounts are surging as "LLM jacking" spreads, turning enterprise LLM seats into recurring-revenue assets for thieves.
By Daniel Okafor3 min read531 words
Program notes
- Chosunbiz reports dark web sales of stolen AI accounts have surged as the scheme known as 'LLM jacking' spreads.
- Hijacked LLM credentials persist as revenue-generating assets for thieves because victims keep paying the subscription bills.
- The report provides no market-size figures, so the scale of listings and prices remains asserted rather than measured.

Sales of stolen AI service accounts on dark web marketplaces have surged, according to a report from South Korean outlet Chosunbiz, as a monetization scheme the industry calls "LLM jacking" spreads among credential thieves.
The term describes a straightforward arbitrage: attackers take over accounts for large language model services — the kind of subscription products that sales, marketing, and support teams now use daily — and resell access at a discount or consume compute themselves. The victim pays the subscription bill. The thief, or the thief's customer, gets the model output.
For revenue teams, the attack surface is unusually broad. A single enterprise may hold dozens of accounts across AI writing assistants, sales copilots, coding agents, and API-based model access. Each one is a recurring-charge asset that, unlike a stolen credit card, keeps producing value for a fraudster week after week until someone notices anomalous usage or an unexpected billing spike. That persistence is what makes hijacked AI credentials attractive inventory compared with one-shot stolen payment data.
The Chosunbiz report does not publish market-level figures for the volume of listings or the average listing price of compromised accounts, so the size of the trade remains asserted rather than measured. What the report does document is directional: supply is rising, and the technique has acquired a name and a distribution pattern serious enough that Korean business media is flagging it to a general audience.
The mechanism follows the standard credential-compromise playbook. Accounts fall to phishing pages, infostealer malware logs, credential stuffing against reused passwords, or session-token theft. From there, the account either changes hands on a marketplace or gets folded into a reseller's pool. OpenAI, Anthropic, Google, and other providers have all confronted unauthorized-access abuse of their platforms, and security vendors tracking infostealer ecosystems have repeatedly reported model-service credentials appearing in stolen log files.
For go-to-market organizations, the practical exposure is twofold. First, there is direct cost: hijacked API keys and subscription seats generate usage bills. Second, and harder to price, there is data exposure. Sales teams paste customer names, deal terms, pricing floors, and internal strategy into AI tools. Whoever controls the account can read that history. A compromised AI seat inside a revenue organization functions as a passive listening post on pipeline, not merely as a billing line item.
Mitigation is unglamorous and already well understood. Enforce SSO and multi-factor authentication on every AI tool an organization pays for, rotate API keys on a schedule, set hard usage and spend alerts so anomalous consumption surfaces in hours rather than billing cycles, and treat AI tool procurement the way finance treats any other SaaS spend — with an owner, an inventory, and periodic access reviews. Shadow AI adopted by individual reps outside procurement is the gap most organizations still cannot see.
Chosunbiz's framing suggests the resale market will keep growing as enterprise AI subscriptions proliferate and as attackers refine account-takeover tooling. Expect security vendors to respond with credential-monitoring services priced to enterprise AI budgets, and expect the next measurable data point — listing counts, average prices, takedown rates — to come from threat-intelligence firms rather than from marketplaces themselves.
via Google News: AI in sales (Source)
More from Daniel Okafor
Show full bio
Correspondent covering marketplaces and e-commerce at Quota Brief.
17 articles
Also rated
- Salesforce Bets Agentic AI Can Become Recurring Revenue
- Salesforce's Agent Meter Could Cost 1,200x Its Own API Rate
- CommanderAI Ships Mobile App for Field Sales Reps in Waste and Scrap
- SalesSparx and Augment Launch SAMI.ai for Healthcare Sales
- Two-Thirds of B2B Buyers Now Prefer Buying Without a Sales Rep