$ techbeacon▋
Phishing

Stolen AWS Keys Enable Hackers to Hijack Amazon Bedrock AI Models in Emerging “LLMjacking” Scheme

Stolen AWS Keys Enable Hackers to Hijack Amazon Bedrock AI Models in Emerging “LLMjacking” Scheme

Security researchers have identified a new attack vector dubbed “LLMjacking,” in which stolen cloud credentials are repurposed to commandeer costly generative‑AI services. The technique was highlighted by FortiGuard Labs after they traced a breach that allowed threat actors to exploit a leaked, long‑lived AWS IAM access key to access Amazon Bedrock, Amazon’s managed platform for large language models.

LLMjacking leverages the fact that many organizations store API keys and IAM credentials for extended periods without regular rotation. When such keys fall into the wrong hands, attackers can bypass traditional perimeter defenses and directly invoke cloud‑based AI APIs, incurring usage fees and potentially extracting proprietary model outputs.

In the reported incident, the compromised IAM key granted unrestricted access to Bedrock’s suite of foundation models. Using the key, the adversaries were able to submit prompts, retrieve generated text, and consume compute resources at the victim’s expense. FortiGuard’s analysis indicated that the key had been active for months before detection, suggesting that the misuse could have generated a significant, unmonitored bill.

Amazon Bedrock offers developers on‑demand access to models from leading AI vendors, pricing usage by the number of tokens processed. Because the service is billed per request, even modest‑scale exploitation can quickly accumulate costs. The breach underscores a growing tension between the rapid adoption of AI capabilities and the maturity of cloud‑security practices.

Experts note that the rise of LLMjacking reflects broader trends: as enterprises integrate generative AI into products and workflows, the associated cloud credentials become high‑value targets. Traditional credential‑theft techniques—phishing, code‑repository leaks, or misconfigured storage—now have a direct line to revenue‑generating AI services, expanding the incentive for cybercriminals.

Mitigation measures recommended by FortiGuard include immediate rotation of any exposed keys, adoption of short‑lived session tokens, and tightening IAM policies to enforce the principle of least privilege. Continuous monitoring of AI‑service usage, coupled with anomaly‑detection tools such as AWS GuardDuty, can help identify abnormal consumption patterns before they translate into large financial losses.

Industry observers anticipate that LLMjacking will become a recurring threat as more organizations rely on third‑party AI platforms. Strengthening credential hygiene, implementing robust audit trails, and educating teams about the risks of long‑lived secrets are seen as essential steps to safeguard both cloud infrastructure and the emerging AI workloads that sit atop it.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related