Hackers are exploiting compromised AI API keys in a technique dubbed “LLMjacking,” gaining unauthorized access to large language model services and generating substantial unexpected bills for affected organizations. The attack method involves stealing credentials that provide access to AI platforms, allowing threat actors to leverage the victim’s account for their own computational purposes without authorization.