Cybercriminals have found a new way to cash in on stolen credentials: selling access to premium AI models like Claude and GPT at rock-bottom prices. According to a recent report by Cybernews, shady online shops are now monetizing compromised accounts by offering cut-rate access to these popular AI tools, turning stolen tokens into a thriving underground business.
How the Black Market for AI Access Works
These illicit storefronts operate in the darker corners of the web, offering login credentials or API access to AI services for a fraction of the regular subscription cost. The stolen tokens are often harvested through phishing campaigns, malware, or data breaches, and then resold to buyers who want to use the AI tools without paying full price.
The report highlights that the prices are so low that even casual users might be tempted, but the risks are significant. Purchasing these accounts not only supports cybercrime but also exposes buyers to potential malware, identity theft, or account lockouts when the original owner notices the unauthorized access.
Why AI Accounts Are a Prime Target
- High value: Premium AI subscriptions can cost $20–$200 per month, making them attractive targets for resale.
- Easy monetization: Unlike credit cards, AI tokens can be used repeatedly without raising immediate red flags.
- Anonymity: Transactions often occur in cryptocurrency, making them harder to trace.
The Rise of Token-Based Cybercrime
This trend reflects a broader shift in cybercriminal strategies. Instead of demanding ransoms or selling credit card numbers, many are now focusing on access-as-a-commodity. Stolen tokens for SaaS tools, gaming platforms, and streaming services are all being sold in bulk, but AI services are particularly lucrative due to their growing demand.
The report suggests that the market for stolen AI access is likely to expand as more businesses and individuals rely on AI for daily tasks. Cybercriminals are also using AI itself to enhance their phishing and credential-stuffing attacks, creating a vicious cycle where AI both enables and is a victim of cybercrime.
How to Protect Yourself
If you use AI services, the report recommends several precautions:
- Enable two-factor authentication (2FA) on all accounts.
- Monitor your account activity for unfamiliar logins or API usage.
- Use unique, strong passwords for each service.
- Be wary of phishing attempts that ask for your login credentials.
Legal and Ethical Implications
Buying stolen AI access is not only unethical but also illegal in most jurisdictions. It violates the terms of service of AI providers and can lead to legal consequences. Moreover, supporting these black markets fuels further cyberattacks, harming individuals and companies alike.
Authorities are increasingly cracking down on such operations, but the decentralized nature of the dark web makes enforcement challenging. The report urges users to stick to official channels and report any suspicious activity to the relevant service providers.
Key Takeaways
- Cybercriminals are selling stolen access to AI models like Claude and GPT at discounted prices.
- These stolen tokens often come from phishing and malware attacks.
- Users should avoid black market deals and secure their own accounts with 2FA.
- This trend highlights the growing intersection of AI and cybercrime.
Zyra